CVE-2019-12498: 3cx Live Chat

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

Affected products

  • 3cx Live Chat: before 8.0.33 (fixed in 8.0.33)

Published 2020-03-20. Last modified 2026-06-17.