Cross-Site Request Forgery Vulnerability in Smartsupp Live Chat by Smartsupp
CVE-2024-38790
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 January 2025
What is CVE-2024-38790?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Smartsupp's live chat, chatbots, AI, and lead generation platform. This security flaw allows an attacker to trick users into executing unwanted actions on behalf of the authenticated user without their consent. The vulnerability poses a risk to users from the initial release of the product through version 3.6. It is crucial for users running affected versions to take appropriate measures to mitigate potential exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Smartsupp β live chat, chatbots, AI and lead generation <= 3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved