Input validation vulnerability in 3CX Free Live Chat 9.4.2

The 3CX Live Chat plugin is a tool available for WordPress websites that allows people to chat with visitors to the website. The plugin has a security flaw in versions up to 9.4.2 that could allow someone to gain access to parts of the website they shouldn’t be able to, like sensitive data or the ability to run malicious code. This is possible because the plugin allows someone to upload and include files of any type, even those that may contain malicious code.

Detected in:

3CX Free Live Chat, Calls & Messaging fixed vulnerable versions:
3CX Free Live Chat, Calls & WhatsApp fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.