๐Ÿ” CVE Alert

CVE-2026-16548

UNKNOWN 0.0

Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload arbitrary files. The original extension is discarded (files are stored under a bare UUID), so this does not yield code execution or stored XSS; impact is bounded to disk consumption and content hosting. The storing path requires the channel's response storage or mail-forwarding to be configured.

Vendor unknown
Product chat widget: floating customer support button for 30+ channels, supporting sms, calls, and chat
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown chat widget: floating customer support button for 30+ channels, supporting sms, calls, and chat

Be the first to know when new unknown vulnerabilities affecting unknown chat widget: floating customer support button for 30+ channels, supporting sms, calls, and chat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat
0 < 1.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/14d5f86b-f0ab-4920-99d0-8e2a66486232/

Credits

Vaibhav Narkhede WPScan