CVE-2019-12498: 3cx Live Chat
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
Affected products
- 3cx Live Chat: before 8.0.33 (fixed in 8.0.33)
Published 2020-03-20. Last modified 2026-06-17.