Impact
The vulnerability allows an unauthenticated user to upload files without any validation of type, extension, content, or size to the plugin’s public response endpoint. Uploaded files are stored under a random UUID in the uploads directory, and the original extension is discarded. Because the plugin does not provide code execution or stored XSS capabilities, the immediate impact is limited to indiscriminate consumption of server disk space and the ability to host arbitrary content that may later be accessed by other users.
Affected Systems
WordPress customers who have installed the "Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat" plugin with a version older than 1.8.2 are affected. The issue requires that the channel response storage or mail-forwarding feature be configured to be exploitable.
Risk and Exploitability
The exploit is delivered through an unauthenticated web request to the response endpoint, so it can be triggered via automated bots or attacker-controlled clients. While there is no risk of code execution or cross‑site scripting, the persistent storage of large or numerous files could lead to broker‑oriented denial of service by exhausting server resources. Because EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, open‑source evidence of real‑world exploitation is currently lacking, suggesting a moderate to low exploitation probability under current conditions.
OpenCVE Enrichment