Facebook Chat Plugin – Live Chat Plugin for WordPress
Facebook Chat Plugin – Live Chat Plugin for WordPress has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2020; all 2 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 7.4 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Access Control.
Every one of the 2 issues recorded for Facebook Chat Plugin – Live Chat Plugin for WordPress has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Chloe Chamberland. Facebook Chat Plugin – Live Chat Plugin for WordPress is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.
CVE-2020-36838Facebook Chat Plugin <= 1.5 - Missing Capabilities Check
Read the full analysisVulnerability Records
Facebook Chat Plugin – Live Chat Plugin for WordPress
Author
Communicate with customers on your website with Messenger-powered chat. Chat Plugin is a chat widget maintained by the Meta Business that enables live chat on your website. Whether they’re on their computer or their phone, website visitors will be able to message you anytime by clicking on a small Messenger chat bubble in the lower right corner of your site. Key features: Website visitors can message you while browsing your site. Set up auto-replies and answers to common questions to serve customers when you’re not available. Continue the conversation with customers on Messenger even after they leave your website. Visitors without a Facebook Messenger account can ask you questions anonymously in Guest mode. Messenger’s familiar interface builds trust. No need to switch between apps to answer questions you get on the website.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C