VYPR
High severity7.4NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-49082

CVE-2026-49082

Description

The Chatway Live Chat plugin <= 1.4.8 exposes subscriber user data, which can be abused in mass-exploit campaigns.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Chatway Live Chat plugin <= 1.4.8 exposes subscriber user data, which can be abused in mass-exploit campaigns.

Vulnerability

The Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin for WordPress versions 1.4.8 and earlier contains a sensitive data exposure vulnerability. This flaw allows unauthorized access to subscriber information, which is normally restricted from unprivileged users. The issue affects all installations of the plugin prior to version 1.4.9.

Exploitation

No authentication or special network position is required beyond standard web access to a vulnerable WordPress site. An attacker can exploit the vulnerability remotely by sending crafted requests to the plugin's endpoints that inadvertently disclose subscriber data [1]. The vulnerability is considered highly dangerous and is expected to be incorporated into mass-exploit campaigns targeting thousands of sites [1].

Impact

Successful exploitation permits a malicious actor to view sensitive information about subscribers, such as personal details or chat histories, that should not be accessible to unauthenticated users [1]. This data exposure can be leveraged to launch further attacks, such as social engineering or account compromise, thereby escalating the breach's scope and severity.

Mitigation

The vendor has released version 1.4.9, which resolves the vulnerability. All users are strongly advised to update to this version immediately [1]. For Patchstack users, enabling auto-update for vulnerable plugins is recommended. No virtual patch is available due to the nature of the flaw, so updating is the only effective mitigation [1].

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1