Live Shopping & Shoppable Videos For WooCommerce Security & Risk Analysis

wordpress.org/plugins/live-shopping-video-streams

Easy-to-install Plugin that adds Live Shopping, Shoppable Videos & Live Commerce as Sales Channels to WooCommerce Stores to Sell & Promote Products

600 active installs v2.2.0 PHP 7.2+ WP 5.0+ Updated Jul 30, 2025
live-sellinglive-shoppinglive-video-shoppingshoppable-videosvideo-commerce
56
C · Use Caution
CVEs total2
Unpatched2
Last CVEDec 31, 2025
Safety Verdict

Is Live Shopping & Shoppable Videos For WooCommerce Safe to Use in 2026?

Use With Caution

Score 56/100

Live Shopping & Shoppable Videos For WooCommerce has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.

2 known CVEs 2 unpatched Last CVE: Dec 31, 2025Updated 8mo ago
Risk Assessment

The "live-shopping-video-streams" v2.2.0 plugin exhibits significant security concerns despite some positive indicators. The static analysis reveals a concerningly small attack surface, but critically, one of the entry points, a REST API route, lacks proper permission callbacks. Furthermore, the presence of the `exec` function, a dangerous function, is a red flag, indicating potential for arbitrary code execution if exploited through an insecure input. The taint analysis shows one flow with an unsanitized path, which could lead to unintended behavior or vulnerabilities. While the plugin demonstrates good practice with 100% of its SQL queries using prepared statements, this is overshadowed by the lack of proper authorization checks and the dangerous function. The vulnerability history, with two medium severity CVEs, both currently unpatched and including common types like Missing Authorization, strongly suggests a recurring pattern of insecure development practices. The most recent vulnerability being "unpatched" as of December 31, 2025, is also a serious indicator of ongoing neglect.

In conclusion, while the plugin utilizes prepared statements for SQL, its security posture is poor due to a lack of authorization checks on its REST API, the use of a dangerous function (`exec`), and a history of unpatched vulnerabilities. The unsanitized path in taint analysis further compounds these risks. This plugin should be considered high-risk and requires immediate attention to address the identified vulnerabilities and implement robust security checks.

Key Concerns

  • Unpatched CVEs (2x Medium)
  • REST API route without permission callbacks
  • Dangerous function: exec
  • Flows with unsanitized paths (1)
  • No nonce checks
  • No capability checks
  • Low output escaping percentage (71%)
Vulnerabilities
2

Live Shopping & Shoppable Videos For WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-62080medium · 4.3Cross-Site Request Forgery (CSRF)

Live Shopping & Shoppable Videos For WooCommerce <= 2.2.0 - Cross-Site Request Forgery

Dec 31, 2025Unpatched
CVE-2025-62081medium · 5.3Missing Authorization

Live Shopping & Shoppable Videos For WooCommerce <= 2.2.0 - Missing Authorization

Dec 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Live Shopping & Shoppable Videos For WooCommerce Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
2 prepared
Unescaped Output
14
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
16
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

exec@exec(escapeshellarg(PHP_BINARY) .' '.escapeshellarg($this->target).' self-update --'.$channel.' --scomposer-setup.php:681

SQL Query Safety

100% prepared2 total queries

Output Escaping

71% escaped49 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<CHLSChannelizeAjax> (includes\CHLSChannelizeAjax\CHLSChannelizeAjax.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Live Shopping & Shoppable Videos For WooCommerce Attack Surface

Entry Points1
Unprotected1

REST API Routes 1

GET/wp-json/apiproductsincludes\CHLSRestApis\CHLSRestApis.php:17
WordPress Hooks 17
actionadmin_noticeschannelize-live-shopping.php:62
actionadmin_menuincludes\Api\CHLSSettingsApi.php:26
actionadmin_enqueue_scriptsincludes\Api\CHLSSettingsApi.php:27
actionwp_enqueue_scriptsincludes\Api\CHLSSettingsApi.php:28
filtertheme_page_templatesincludes\Api\CHLSSettingsApi.php:29
filtertemplate_includeincludes\Api\CHLSSettingsApi.php:30
actioninitincludes\Api\CHLSSettingsApi.php:31
actioninitincludes\Api\CHLSSettingsApi.php:32
actionwp_loginincludes\Api\CHLSSettingsApi.php:33
actionclear_auth_cookieincludes\Api\CHLSSettingsApi.php:34
actionuser_registerincludes\Api\CHLSSettingsApi.php:35
actionprofile_updateincludes\Api\CHLSSettingsApi.php:36
actiondelete_userincludes\Api\CHLSSettingsApi.php:37
actionwoocommerce_thankyouincludes\Api\CHLSSettingsApi.php:38
actiontemplate_redirectincludes\CHLSChannelizeAjax\CHLSChannelizeAjax.php:34
actionrest_api_initincludes\CHLSRestApis\CHLSRestApis.php:16
filterrest_pre_serve_requestincludes\CHLSRestApis\CHLSRestApis.php:23
Maintenance & Trust

Live Shopping & Shoppable Videos For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 30, 2025
PHP min version7.2
Downloads8K

Community Trust

Rating100/100
Number of ratings8
Active installs600
Developer Profile

Live Shopping & Shoppable Videos For WooCommerce Developer Profile

Channelize.io Team

2 plugins · 620 total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Live Shopping & Shoppable Videos For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-shopping-video-streams/assets/css/style.css/wp-content/plugins/live-shopping-video-streams/assets/js/main.js
Script Paths
/wp-content/plugins/live-shopping-video-streams/assets/js/main.js
Version Parameters
live-shopping-video-streams/assets/css/style.css?ver=live-shopping-video-streams/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
chls-admin-pagechannelize-live-shop
Data Attributes
data-channelize-live-shop
JS Globals
CHLS_API_URLChannelizeLiveShop
Shortcode Output
[channelize_live_shop]
FAQ

Frequently Asked Questions about Live Shopping & Shoppable Videos For WooCommerce