Impact
The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress contains a stored Cross‑Site Scripting flaw in the 'chatra‑code' configuration option. An authenticated user with administrator or higher privileges can insert arbitrary JavaScript into that setting because the input is not properly sanitized or escaped. The injected script is then rendered on any page that includes the setting, causing it to run in the browsers of visitors when they access the page. This vulnerability is catalogued as CWE‑79.
Affected Systems
WordPress installations running the Chatra Live Chat + ChatBot + Cart Saver plugin up to and including version 1.0.12. The flaw impacts only multisite networks and installations where the unfiltered_html capability has been disabled, which is typical for standard configurations.
Risk and Exploitability
The CVSS score of 4.4 reflects moderate severity because exploitation requires administrator‑level access. The EPSS score of less than 1 % indicates a low probability of active exploitation. The flaw is not listed in the CISA KEV catalog, implying that no widespread exploitation is known. An attacker who meets the role requirement can inject scripts that will run in users’ browsers on any page that loads the compromised setting.
OpenCVE Enrichment