Executive brief
A vulnerability in the Chatway Live Chat plugin for WordPress allows users with low-level 'Subscriber' accounts to access sensitive information that should be restricted. This plugin is used to provide customer support and AI chatbot functionality on websites. An attacker could exploit this to gain unauthorized access to private data, potentially leading to further compromise of the site or its users.
Technical details
The Chatway Live Chat plugin (versions 1.4.8 and below) for WordPress contains a sensitive data exposure vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). The flaw allows an authenticated attacker with Subscriber-level privileges to access sensitive information that is normally restricted from regular users. The vulnerability is reachable over the network without user interaction. The issue has been addressed in version 1.4.9 of the plugin.
Affected products
- Chatway Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8
Timeline
- 2026-04-30: other: Reported by researcher dodoh4t
- 2026-06-05: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date