WordPress Plugin Vulnerabilities

Chat Help < 3.1.4 - Unauthenticated Sensitive Information Exposure

Description

The plugin is vulnerable to Sensitive Information Exposure via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and authorization checks. This makes it possible for unauthenticated attackers to extract sensitive data including customer names, email addresses, phone numbers, WhatsApp messages, complete geolocation data (IP addresses, city, country, ISP, coordinates), device fingerprinting information (browser, OS, screen resolution), and WordPress account credentials (user IDs, usernames, emails, names) for logged-in users who submit forms.

Affects Plugins

Fixed in 3.1.4

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
NumeX
Verified
No

Timeline

Publicly Published
2025-11-18 (about 10 months ago)
Added
2026-01-19 (about 8 months ago)
Last Updated
2026-01-19 (about 8 months ago)

Other