Skip to main content
A weathered brushed metal intercom panel filling the frame, with rows of identical worn call buttons.
Photo by Stephanie Harlacher on Unsplash
  1. Archive/

Stored XSS in Three WordPress Chat Plugins

Patrik Grobshäuser
Author
Patrik Grobshäuser
Security researcher at Assetnote / Searchlight Cyber. Before that, seven years triaging other people’s reports at HackerOne and Shopify. Hunting bugs since 2012, published as Patrik Fehrenbach until 2025.
Table of Contents

During an installation for one of our customers, we had to install a suitable chat plugin for WordPress. There are a lot of them but we decided to choose the first one that comes in the row. Due to the fact that we like security we of course tested the plugins against some well known vulnerabilities, the result was frustrating. Every single plugin of those we’ve tested is vulnerable to stored cross site scripting.

Disclosure
#

Since we are white hats we’ve reported all of them first to the vendors, only one of them (WP Live Chat Support) answered us and wanted more information, big thumbs up to them! For this reason we’ve waited to publish this until they’ve fixed the issue.

Affected plugins
#

  1. WP Live Chat Support — stored cross-site scripting

  2. MyLiveChat — stored cross-site scripting

  3. Provide Support — stored cross-site scripting

Related