← Vulnerability feed

Vulnerability record · CVE-2014-10386 · published 22 August 2019

CVE-2014-10386: 3cx live chat injection vulnerability

3cx · Live Chat

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

6.1 CVSS 3.0 Medium EPSS 0.91% · top 41.5% CWE-74 · Injection
6.1CVSS 3.0 base score, v2 4.3
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-10386 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-124983cx live chat missing authorization vulnerabilityThe WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection …EPSS 2.0%9.8CVE-2019-111853cx live chat unrestricted file upload vulnerabilityThe WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete pat…EPSS 4.3%9.8CVE-2018-124263cx live chat unrestricted file upload vulnerabilityThe WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation …EPSS 5.1%6.1CVE-2017-185073cx live chat cross-site scripting vulnerabilityThe wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.EPSS 0.92%6.1CVE-2019-149503cx live chat cross-site scripting vulnerabilityThe wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.EPSS 1.2%6.1CVE-2016-108793cx live chat cross-site scripting vulnerabilityThe wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.EPSS 0.93%6.1CVE-2017-185083cx live chat cross-site scripting vulnerabilityThe wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.EPSS 0.93%6.1CVE-2019-99133cx live chat cross-site scripting vulnerabilityThe wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2014-10386), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.