Impact
The flaw is improper neutralization of input during web page generation, allowing stored XSS attacks within the Dialogity Free Live Chat plugin. An attacker can inject malicious script into chat content, which is then rendered unfiltered whenever a page containing the chat is viewed. This can lead to session hijacking, data theft, or site defacement by executing code within the victim’s browser.
Affected Systems
Dialogity Free Live Chat, a WordPress plugin, is vulnerable in all releases up through version 1.0.3. The vulnerability exists in the core chat functionality that displays stored messages, so any WordPress site that installs this plugin and uses its chat component is at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation in the wild is unlikely at present. The plugin is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves adding or modifying chat messages—either by an administrator or a trusted user—that contain malicious code; once stored, the code will execute in the browsers of all visitors who view the chat. An attacker with the ability to influence chat content can therefore impact many site users without needing additional access.
OpenCVE Enrichment
EUVD