CVE-2026-49082
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-49082 is a Subscriber Sensitive Data Exposure vulnerability in the Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons WordPress plugin, affecting versions 1.4.8 and earlier. The vulnerability was discovered and disclosed on June 15, 2026, with a patch available as of version 1.4.9. It was assigned a CVSS v3.1 base score of 7.4 (High) by Patchstack, the reporting CNA (GitHub Advisory, Patchstack).

Technical details

The vulnerability is classified under CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin transmits data to actors who should not have access to it — in this case, low-privileged authenticated users (subscribers) can access sensitive subscriber data that should be restricted. The attack vector is network-based, requires low privileges, no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. No public proof-of-concept or detailed technical write-up describing the specific vulnerable endpoint or payload has been published at this time (GitHub Advisory, Patchstack).

Impact

An authenticated user with subscriber-level (low) privileges can access sensitive subscriber data, potentially modify data, and cause limited service disruption. The changed scope in the CVSS rating indicates that the impact extends beyond the plugin itself, potentially exposing chat conversation data, customer support records, or other personally identifiable information stored by the plugin. This could result in privacy violations, unauthorized data access, and limited integrity and availability impacts on the affected WordPress installation (GitHub Advisory, Patchstack).

Mitigation and workarounds

The primary remediation is to upgrade the Chatway Live Chat plugin to version 1.4.9 or later, which addresses this vulnerability. As a workaround, site administrators should restrict plugin access to only authorized users with appropriate privilege levels and audit existing subscriber accounts for unauthorized access. The patch details are available via GitHub Advisory GHSA-7q28-f9qc-33fv (GitHub Advisory, Patchstack).

Community reactions

The vulnerability was reported by Patchstack and received standard coverage in WordPress security tracking resources. Wordfence included it in their weekly WordPress vulnerability report for the period of June 1–7, 2026. No notable researcher commentary or significant community discussion has been observed beyond routine vulnerability tracking (Wordfence Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8789HIGH8.1
  • easy-appointments
NoYesJul 24, 2026
CVE-2026-10033HIGH7.3
  • eventon-action-user
NoYesJul 24, 2026
CVE-2026-15401HIGH7.2
  • vikbooking
NoYesJul 24, 2026
CVE-2026-15821MEDIUM6.4
  • suredash
NoYesJul 24, 2026
CVE-2026-15739MEDIUM6.4
  • widget-google-reviews
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management