Chat Help
- <= 3.1.3
A vulnerability allowing sensitive information exposure exists in the Chat Help – Click to Chat Button & Form plugin for WordPress, in all versions through 3.1.3. The issue arises from the plugin's REST API endpoints, which lack proper authentication and authorization checks. This vulnerability enables unauthenticated attackers to access sensitive data such as customer names, email addresses, phone numbers, WhatsApp messages, full geolocation details (including IP addresses, city, country, ISP, and coordinates), device fingerprinting data (browser, operating system, screen resolution), and WordPress account information (user IDs, usernames, emails, names) of logged-in users who have submitted forms.
Exploitation of this vulnerability could lead to unauthorized access to sensitive personal information, including contact details, geolocation data, device information, and WordPress account credentials of users who submitted forms.
Users are advised to update the Chat Help – Click to Chat Button & Form plugin to version 3.1.4 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.