wp-live-chat-support plugin before 8.0.27 for WordPress contains a reflected cross-site scripting caused by insufficient sanitization in the GDPR page, letting attackers execute arbitrary scripts in the context of the victim's browser, exploit requires victim to visit a malicious page.
id: CVE-2019-14950
info:
name: WP Live Chat Support <= 8.0.27 — Stored Cross-Site Scripting
aut
...