
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49082 is a Subscriber Sensitive Data Exposure vulnerability in the Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons WordPress plugin, affecting versions 1.4.8 and earlier. The vulnerability was discovered and disclosed on June 15, 2026, with a patch available as of version 1.4.9. It was assigned a CVSS v3.1 base score of 7.4 (High) by Patchstack, the reporting CNA (GitHub Advisory, Patchstack).
The vulnerability is classified under CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin transmits data to actors who should not have access to it — in this case, low-privileged authenticated users (subscribers) can access sensitive subscriber data that should be restricted. The attack vector is network-based, requires low privileges, no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. No public proof-of-concept or detailed technical write-up describing the specific vulnerable endpoint or payload has been published at this time (GitHub Advisory, Patchstack).
An authenticated user with subscriber-level (low) privileges can access sensitive subscriber data, potentially modify data, and cause limited service disruption. The changed scope in the CVSS rating indicates that the impact extends beyond the plugin itself, potentially exposing chat conversation data, customer support records, or other personally identifiable information stored by the plugin. This could result in privacy violations, unauthorized data access, and limited integrity and availability impacts on the affected WordPress installation (GitHub Advisory, Patchstack).
The primary remediation is to upgrade the Chatway Live Chat plugin to version 1.4.9 or later, which addresses this vulnerability. As a workaround, site administrators should restrict plugin access to only authorized users with appropriate privilege levels and audit existing subscriber accounts for unauthorized access. The patch details are available via GitHub Advisory GHSA-7q28-f9qc-33fv (GitHub Advisory, Patchstack).
The vulnerability was reported by Patchstack and received standard coverage in WordPress security tracking resources. Wordfence included it in their weekly WordPress vulnerability report for the period of June 1–7, 2026. No notable researcher commentary or significant community discussion has been observed beyond routine vulnerability tracking (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."