Impact
The AtomChat plugin for WordPress contains a stored cross‑site scripting flaw due to improper neutralization of input during web page generation. A malicious actor can inject script into chat content that is persisted and displayed to other visitors, potentially allowing cookie theft, session hijacking, or execution of arbitrary client‑side code. This reflects the weakness defined as CWE‑79.
Affected Systems
WordPress sites utilizing the Team AtomChat AtomChat plugin versions from the earliest release up to and including 1.1.8 are affected. Versions newer than 1.1.8 are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS of less than 1 % suggests a very low likelihood of exploitation. The bug is not catalogued in CISA’s KEV database. Attackers would need to supply malicious content to the plugin’s stored chat feature, then entice a legitimate user to view that content within a browser. The vulnerability does not allow remote code execution on the server but can compromise client‑side security.
OpenCVE Enrichment
EUVD