CVE-2019-14950: XSS
Published Aug 12, 2019
·Updated
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
Affected Software
1 affected component
3CX Live Chat Wordpress<8.0.27
Event History
Aug 12, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14950?
CVE-2019-14950 is a vulnerability in the wp-live-chat-support plugin before version 8.0.27 for WordPress, which allows for cross-site scripting (XSS) attacks via the GDPR page.
2
How can the wp-live-chat-support plugin be affected?
The wp-live-chat-support plugin is affected if the version is earlier than 8.0.27 for WordPress.
3
What is the severity level of CVE-2019-14950?
CVE-2019-14950 has a severity level of medium with a CVSS score of 6.1.
4
How can I fix the CVE-2019-14950 vulnerability?
To fix the CVE-2019-14950 vulnerability, update the wp-live-chat-support plugin to version 8.0.27 or later.
5
Where can I get more information about the wp-live-chat-support plugin?
More information about the wp-live-chat-support plugin can be found on the WordPress plugin directory: https://wordpress.org/plugins/wp-live-chat-support/#developers