Description
The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and authorization checks. This makes it possible for unauthenticated attackers to extract sensitive data including customer names, email addresses, phone numbers, WhatsApp messages, complete geolocation data (IP addresses, city, country, ISP, coordinates), device fingerprinting information (browser, OS, screen resolution), and WordPress account credentials (user IDs, usernames, emails, names) for logged-in users who submit forms.
Published: 2026-07-10
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Chat Help – Click to Chat Button & Form plugin for WordPress contains a missing authorization flaw that allows attackers to read private data through its REST API endpoints. Because the plugin does not enforce authentication or authorization, any unauthenticated user can retrieve customer names, email addresses, phone numbers, WhatsApp messages, full geolocation data, device fingerprinting information, and even WordPress account credentials of logged‑in users who submit the chat form. This represents a significant confidentiality breach and could enable credential‑based attacks.

Affected Systems

All installations of the plugin version 3.1.3 or earlier, including 3.1.1 and earlier, of the vendor themeatelier’s products "Chat Help – Click to Chat Button" and "WooCommerce Chat to Order & Floating Chat Form" are impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of < 1 % reflects a very low current exploitation probability. The flaw can be exploited simply by sending unauthenticated HTTP requests to the endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. Although the vulnerability is not listed in the CISA KEV catalog, the potential for mass data leakage and subsequent credential‑based exploitation makes it a serious threat.

Generated by OpenCVE AI on July 29, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Chat Help – Click to Chat Button & Form plugin to the latest version released by themeatelier.
  • If an update is not immediately possible, block the vulnerable REST endpoints by adding rewrite rules in .htaccess or modifying the server configuration to deny access to /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id} for unauthenticated users.
  • Add custom code or use a REST API restriction plugin to require authentication for all /wp-json/chat-help/v1/* routes, ensuring that only logged‑in users can access lead data.

Generated by OpenCVE AI on July 29, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Themeatelier
Themeatelier chathelp – Click To Chat Button, Woocommerce Chat To Order & Floating Chat Form
Wordpress
Wordpress wordpress
Vendors & Products Themeatelier
Themeatelier chathelp – Click To Chat Button, Woocommerce Chat To Order & Floating Chat Form
Wordpress
Wordpress wordpress

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and authorization checks. This makes it possible for unauthenticated attackers to extract sensitive data including customer names, email addresses, phone numbers, WhatsApp messages, complete geolocation data (IP addresses, city, country, ISP, coordinates), device fingerprinting information (browser, OS, screen resolution), and WordPress account credentials (user IDs, usernames, emails, names) for logged-in users who submit forms.
Title Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Themeatelier Chathelp – Click To Chat Button, Woocommerce Chat To Order & Floating Chat Form
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-10T13:16:42.262Z

Reserved: 2026-07-09T15:51:39.452Z

Link: CVE-2026-15291

cve-icon Vulnrichment

Updated: 2026-07-10T13:16:35.972Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses