Input validation vulnerability in Click to Chat – HoliThemes 3.35

The Click to Chat – HoliThemes plugin for WordPress has a security issue that affects all versions up to 3.35. This vulnerability, known as Local File Inclusion, allows attackers with contributor access or higher to access and run any files they want on the server. This means they can run any code written in those files, which could bypass security measures, access confidential information, or even cause the website to execute malicious code. This is especially dangerous because it can happen even if the attacker uploads seemingly harmless files like images.

Detected in:

Click to Chat – HoliThemes fixed vulnerable versions: >= * <= 3.35

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.