During an installation for one of our customers, we had to install a suitable chat plugin for WordPress. There are a lot of them but we decided to choose the first one that comes in the row. Due to the fact that we like security we of course tested the plugins against some well known vulnerabilities, the result was frustrating. Every single plugin of those we’ve tested is vulnerable to stored cross site scripting.
Disclosure#
Since we are white hats we’ve reported all of them first to the vendors, only one of them (WP Live Chat Support) answered us and wanted more information, big thumbs up to them! For this reason we’ve waited to publish this until they’ve fixed the issue.
Affected plugins#
WP Live Chat Support — stored cross-site scripting
MyLiveChat — stored cross-site scripting
Provide Support — stored cross-site scripting




