Description
Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from n/a through <= 4.4.7.
Published: 2025-05-07
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LiveAgent plugin for WordPress contains a CSRF flaw that permits attackers to forge authenticated requests on behalf of a logged‑in user. By embedding a crafted form or link in a malicious page, a victim can be tricked into initiating actions such as modifying plugin settings or submitting content without their consent, leading to a loss of data integrity for the site. Based on the nature of CSRF, it is inferred that an active authenticated session is required for exploitation.

Affected Systems

All WordPress sites that have the qusupport LiveAgent plugin installed in any version from the earliest available through 4.4.7 are potentially vulnerable. Versions newer than 4.4.7 are assumed to have the issue fixed.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity vulnerability. The EPSS estimate of less than 1% points to a low likelihood of active exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Exploitation is expected to require a victim user to be authenticated to the WordPress site while visiting a malicious or compromised page so that the forged request is automatically sent to the LiveAgent endpoints. Overall, the risk remains moderate but the probability of widespread attacks is considered low.

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LiveAgent plugin to version 4.4.8 or later
  • Implement CSRF token validation and confirm request origins for all LiveAgent form submissions
  • Configure the plugin’s endpoints to use same‑site or strict cookie attributes
  • Restrict configuration and critical actions of the LiveAgent plugin to administrator‑only roles

Generated by OpenCVE AI on April 30, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13733 Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7. Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from n/a through <= 4.4.7.
Title WordPress LiveAgent <= 4.4.7 - Cross Site Request Forgery (CSRF) Vulnerability WordPress LiveAgent plugin <= 4.4.7 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}

epss

{'score': 0.0002}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7.
Title WordPress LiveAgent <= 4.4.7 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:48.751Z

Reserved: 2025-05-07T10:45:27.458Z

Link: CVE-2025-47667

cve-icon Vulnrichment

Updated: 2025-05-07T17:18:57.306Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:19.040

Modified: 2026-04-23T15:30:42.700

Link: CVE-2025-47667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:30:26Z

Weaknesses