Description
WordPress Plugin WP-Live Chat by 3CX is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin WP-Live Chat by 3CX version 8.0.28 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 8.0.29 or latest
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1901)
WordPress Plugin SMTP Mail Cross-Site Scripting (1.3.1)
WordPress Plugin Salon Booking System Cross-Site Scripting (6.3)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-0827)
WordPress Plugin Relocate Upload 'abspath' Parameter Remote File Include (0.14)