Impact
The Chat Help – Click to Chat Button & Form plugin for WordPress contains a missing authorization flaw that allows attackers to read private data through its REST API endpoints. Because the plugin does not enforce authentication or authorization, any unauthenticated user can retrieve customer names, email addresses, phone numbers, WhatsApp messages, full geolocation data, device fingerprinting information, and even WordPress account credentials of logged‑in users who submit the chat form. This represents a significant confidentiality breach and could enable credential‑based attacks.
Affected Systems
All installations of the plugin version 3.1.3 or earlier, including 3.1.1 and earlier, of the vendor themeatelier’s products "Chat Help – Click to Chat Button" and "WooCommerce Chat to Order & Floating Chat Form" are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of < 1 % reflects a very low current exploitation probability. The flaw can be exploited simply by sending unauthenticated HTTP requests to the endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. Although the vulnerability is not listed in the CISA KEV catalog, the potential for mass data leakage and subsequent credential‑based exploitation makes it a serious threat.
OpenCVE Enrichment