Cross-Site Request Forgery Vulnerability in Casengo Live Chat Support
CVE-2025-58688
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-58688?
The Casengo Live Chat Support plugin presents a Cross-Site Request Forgery (CSRF) vulnerability that can be exploited to execute stored XSS attacks. This vulnerability affects all versions up to 2.1.4, allowing malicious entities to manipulate chat interactions potentially leading to unauthorized actions on behalf of legitimate users, compromising the integrity of communication and security within the web application.
Affected Version(s)
Casengo Live Chat Support <= 2.1.4