WordPress Plugin Vulnerabilities
Chat Help < 3.1.4 - Unauthenticated Sensitive Information Exposure
Description
The plugin is vulnerable to Sensitive Information Exposure via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and authorization checks. This makes it possible for unauthenticated attackers to extract sensitive data including customer names, email addresses, phone numbers, WhatsApp messages, complete geolocation data (IP addresses, city, country, ISP, coordinates), device fingerprinting information (browser, OS, screen resolution), and WordPress account credentials (user IDs, usernames, emails, names) for logged-in users who submit forms.
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
NumeX
Verified
No
WPVDB ID
Timeline
Publicly Published
2025-11-18 (about 10 months ago)
Added
2026-01-19 (about 8 months ago)
Last Updated
2026-01-19 (about 8 months ago)