Impact
The flaw resides in the Chaport Live Chat WordPress plugin, where input is improperly sanitized before being rendered on web pages, allowing an attacker to inject arbitrary JavaScript that is stored and later executed in the browsers of users who view the affected page. This can lead to defacement, credential theft, or other client‑side attacks against site visitors. The weakness is a classic input validation issue categorized as CWE-79.
Affected Systems
Any WordPress site that has the Chaport Live Chat plugin installed with a version through 1.1.6 is vulnerable. The affected product name is Chaport Live Chat and the vulnerability applies to all installed copies of versions n/a up to and including 1.1.6.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is through the chat interface or administrative entry forms where user input is stored and rendered without proper escaping; an attacker would need access to the page that displays the stored data, such as by becoming a user of the site or exploiting another vulnerability to inject the payload.
OpenCVE Enrichment
EUVD