Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11.
Published: 2025-07-04
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation leads to a stored cross‑site scripting vulnerability in the Chatra Live Chat + ChatBot + Cart Saver plugin. Attackers can inject arbitrary HTML or JavaScript into content that the plugin stores and later serves to visitors. If successfully exploited, malicious scripts run in the browser context of any site user viewing the affected pages, potentially enabling credential theft, session hijacking, or defacement. The weakness is identified as CWE‑79.

Affected Systems

The vulnerability affects the Chatra Live Chat + ChatBot + Cart Saver WordPress plugin in all releases dated from its earliest available version up through 1.0.11. Any WordPress installation that has this plugin installed and not yet upgraded beyond version 1.0.11 is susceptible. No specific operating system or WordPress core version restriction is noted.

Risk and Exploitability

The CVSS base score of 7.7 indicates high severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, implying it has not yet been observed in widespread real‑world attacks. The likely attack vector is exploitation through any stored input field within the plugin, such as chat message or configuration settings, that is rendered without proper escaping. Users with administrative or content‑authoring privileges could be used to embed malicious payloads that are subsequently delivered to all site visitors.

Generated by OpenCVE AI on May 1, 2026 at 07:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest release of the Chatra Live Chat + ChatBot + Cart Saver plugin, version 1.0.12 or newer, to eliminate the XSS flaw.
  • After updating, audit the database for any residual malicious script content stored by the plugin and remove it to prevent execution.
  • Run a comprehensive security scan of the site to verify that no cross‑site scripting vulnerabilities remain and that the plugin’s input handling is correctly sanitized.

Generated by OpenCVE AI on May 1, 2026 at 07:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19958 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Tue, 08 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 09:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11.
Title WordPress Chatra Live Chat + ChatBot + Cart Saver plugin <= 1.0.11 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:33.252Z

Reserved: 2025-01-23T14:52:51.691Z

Link: CVE-2025-24735

cve-icon Vulnrichment

Updated: 2025-07-08T14:17:51.365Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T09:15:26.210

Modified: 2026-04-28T19:29:30.653

Link: CVE-2025-24735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:15:11Z

Weaknesses