Vulnerability record · CVE-2019-11185 · published 3 June 2019
CVE-2019-11185: 3cx live chat unrestricted file upload vulnerability
3cx · Live Chat
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to pass MIME checks. Specifically, an unauthenticated remote user submits a crafted file upload POST request to the REST api remote_upload endpoint. The file contains data that will fool the plugin's MIME check into classifying it as an image (which is a whitelisted file extension) and finally a trailing .phtml file extension.
Description
The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to pass MIME checks. Specifically, an unauthenticated remote user submits a crafted file upload POST request to the REST api remote_upload endpoint. The file contains data that will fool the plugin's MIME check into classifying it as an image (which is a whitelisted file extension) and finally a trailing .phtml file extension.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wordpress.org/plugins/wp-live-chat-support/#developers | Third Party Advisory |
| https://wp-livechat.com/ | Vendor Advisory |
| https://wpvulndb.com/vulnerabilities/9320 | ExploitThird Party Advisory |
| https://wordpress.org/plugins/wp-live-chat-support/#developers | Third Party Advisory |
| https://wp-livechat.com/ | Vendor Advisory |
| https://wpvulndb.com/vulnerabilities/9320 | ExploitThird Party Advisory |
Track CVE-2019-11185 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11185), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.