peter bassill · operator
$ cve CVE-2019-11185 JSON

CVE-2019-11185

9.8
CRITICAL · CVSS 3.0 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to pass MIME checks. Specifically, an unauthenticated remote user submits a crafted file upload POST request to the REST api remote_upload endpoint. The file contains data that will fool the plugin's MIME check into classifying it as an image (which is a whitelisted file extension) and finally a trailing .phtml file extension.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.35% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2019-06-03
Last modified2026-06-17

Affected (1)

VendorProduct
3cxlive chat

References

→ the Explorer  ·  watch your stack  ·  NVD