CVE-2025-66099: WordPress Chat Help plugin <= 3.1.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66099?
The severity of CVE-2025-66099 is classified as high due to the potential for unauthorized access to sensitive functionalities.
How do I fix CVE-2025-66099?
To fix CVE-2025-66099, update the ThemeAtelier Chat Help plugin to version 3.1.4 or later, which addresses the missing authorization issue.
What types of systems are affected by CVE-2025-66099?
CVE-2025-66099 affects ThemeAtelier Chat Help versions from n/a through 3.1.3, including the WordPress Chat Help extension.
What kind of attacks can exploit CVE-2025-66099?
CVE-2025-66099 can be exploited through unauthorized access to restricted chat functionalities, potentially leading to data leakage.
What are the consequences of ignoring CVE-2025-66099?
Ignoring CVE-2025-66099 may result in unauthorized users gaining access to chat data and potentially compromising the integrity of user interactions.