PT-2026-67665 · WordPress · Chat Widget: Floating Customer Support Button For 30+ Channels

·

CVE-2026-16548

·

Published

2026-08-04

·

Updated

2026-08-11

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin versions prior to 1.8.2
Description An unauthenticated user can upload arbitrary files because the plugin fails to validate the type, extension, content, or size of files submitted to its public response endpoint. These files are stored in the uploads directory. Since the original extension is discarded and files are stored using a bare UUID (Universally Unique Identifier), this issue does not allow for code execution or stored XSS (Cross-Site Scripting). The impact is limited to content hosting and disk consumption. This issue requires the channel's response storage or mail-forwarding to be configured.
Recommendations Update the plugin to version 1.8.2 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16548

Affected Products

Chat Widget: Floating Customer Support Button For 30+ Channels