TOCHAT.BE
TOCHAT.BE has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. TOCHAT.BE is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-57915TOCHAT.BE <= 1.3.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

TOCHAT.BE
Author
César Martín
Add a WhatsApp click to chat button on your website for free. WhatsApp is the most used messenger app in the world. WordPress is the best platform to present your business to the world. Make your customers connect with you with a click. It is very easy and simple. Just install this free plugin and you can connect your WhatsApp account with your WordPress website and communicate with your users. This plugin offers free multiagent support and logs all the messages so you can keep track of your customers. Also, you can configure the look and feel easy. Create the best experience for your customers and users enabling WhatsApp on your website. FEATURES LIST: Multi Agents Just WhatsApp Icon Fully Responsive Fully Customizable GDPR Ready Auto Popup Shortcode Generator Enable/Disable on Mobile Devices Enable/Disable on Desktops and Laptops Change Popup Location Custom Welcome Message Purchase Premium Plugin
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C