Input validation vulnerability in Tidio – Live Chat & Chatbots 4.2.1

The Tidio Live Chat plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that versions up to, and including, 4.2.0 are not properly protected against malicious code being inserted into the website. This code can then be executed on the website when a user visits the affected page, and it could also be used to perform administrative actions. To protect against this attack, administrators should make sure that they are using the most recent version of the Tidio Live Chat plugin.

Detected in:

Tidio – Live Chat & AI Chatbots fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.