Input validation vulnerability in 3CX Free Live Chat 4.3.5

The WP Live Chat Support plugin for WordPress is vulnerable to a security issue called blind SQL Injection. This vulnerability affects versions up to and including 4.3.5. It happens when there is not enough security in the way user-supplied information is handled, and when not enough preparation is done on the existing SQL query. This makes it possible for attackers who do not need to be authenticated to add extra SQL queries to existing ones and use them to get sensitive information from the database.

Detected in:

3CX Free Live Chat, Calls & Messaging fixed vulnerable versions:
3CX Free Live Chat, Calls & WhatsApp fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.