Blazeo
Blazeo has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Blazeo has a vendor fix available, so running the current release closes it.
All of these findings were reported by Yuki Haruma. Blazeo is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2023-28414ApexChat <= 1.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
Read the full analysisVulnerability Records
Blazeo
Author
Razi Abbasi
Blazeo provides a complete, turnkey chat service. We use our own industry-trained live chat agents and software platform to service chats. This means major cost savings as we eliminate the need to take your key employees away from their core responsibilities to handle chats or hire and train anyone to get started. Blazeo has you covered 24/7. On average, 42 percent of leads converted via live chat occur after the typical business hours of 9 AM to 5 PM. Without around-the-clock coverage, you may be missing nearly half the leads you could be getting from your Live Chat provider. Blazeo charges only for actual qualified leads that are sent to you. There is no minimum recurring charge or long-term contract making Blazeo easy to try. You can cancel our service at any time without any penalty. For this plugin to work successfully, you should have a subscription to the Blazeo service. Please note: Installing this plugin will make a call to Blazeo’s servers to retrieve and display the chat software. Arbitrary section A brief Markdown Example
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C