CVE-2025-66099
Description
Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chat Help: from n/a through <= 3.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WordPress Chat Help plugin versions ≤ 3.1.3 allows unauthenticated attackers to exploit incorrectly configured access controls.
CVE-2025-66099 is a missing authorization vulnerability in the WordPress Chat Help plugin by ThemeAtelier, affecting all versions up to and including 3.1.3. The root cause is a broken access control mechanism—specifically, a missing authorization or authentication check in a function that should require higher privileges. This allows unprivileged users to perform actions meant for higher-privileged roles [1].
To exploit this vulnerability, an attacker needs no authentication (or only low privileges) and can trigger the flaw over the network. The attack complexity is low, and no user interaction is required. The issue is classified as a broken access control vulnerability, which is commonly used in mass-exploit campaigns targeting thousands of websites regardless of their size or popularity [1].
Successful exploitation grants an attacker the ability to perform actions that bypass the intended access control security levels, potentially leading to unauthorized data access, modification, or other privilege escalation scenarios. The CVSS v3 base score is 5.3 (Medium), with the impact being of low severity according to the advisory [1].
The vendor has released a fix in version 3.1.4. Users are strongly advised to update to 3.1.4 or later. Patchstack users can enable auto-updates for vulnerable plugins. If unable to update immediately, users should contact their hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=3.1.3+ 1 more
- (no CPE)range: <=3.1.3
- (no CPE)range: <= 3.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.