PT-2026-67665 · WordPress · Chat Widget: Floating Customer Support Button For 30+ Channels
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin versions prior to 1.8.2
Description
An unauthenticated user can upload arbitrary files because the plugin fails to validate the type, extension, content, or size of files submitted to its public response endpoint. These files are stored in the uploads directory. Since the original extension is discarded and files are stored using a bare UUID (Universally Unique Identifier), this issue does not allow for code execution or stored XSS (Cross-Site Scripting). The impact is limited to content hosting and disk consumption. This issue requires the channel's response storage or mail-forwarding to be configured.
Recommendations
Update the plugin to version 1.8.2 or later.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chat Widget: Floating Customer Support Button For 30+ Channels