Chat Help WordPress Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure exists in the Chat Help – Click to Chat Button & Form plugin for WordPress, in all versions through 3.1.3. The issue arises from the plugin's REST API endpoints, which lack proper authentication and authorization checks. This vulnerability enables unauthenticated attackers to access sensitive data such as customer names, email addresses, phone numbers, WhatsApp messages, full geolocation details (including IP addresses, city, country, ISP, and coordinates), device fingerprinting data (browser, operating system, screen resolution), and WordPress account information (user IDs, usernames, emails, names) of logged-in users who have submitted forms.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive personal information, including contact details, geolocation data, device information, and WordPress account credentials of users who submitted forms.

Remediation

Users are advised to update the Chat Help – Click to Chat Button & Form plugin to version 3.1.4 or a newer patched version.

Added: Jul 10, 2026, 5:42 AM
Updated: Jul 10, 2026, 5:42 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
9.3
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.