Impact
The ChatHelp plugin for WordPress contains a stored cross‑site scripting vulnerability that arises when the 'number' and 'group' attributes in its shortcodes are not properly sanitized. Attackers with contributor‑level or higher access can insert malicious script code into these attributes, which is stored in the database and rendered unescaped into the page output. When any site visitor loads a page containing the affected shortcode, the injected script runs in the visitor’s browser, potentially enabling the attacker to perform actions such as defacement or unauthorized data exfiltration.
Affected Systems
WordPress installations using themeatelier’s ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin in any version up to 3.5.1 are vulnerable. Site administrators should identify whether these plugin versions are active and verify the installed revision.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the short term. The vulnerability is not cataloged in CISA’s KEV. Exploitation requires an authenticated user with at least contributor privilege who can add or edit the shortcode; once the malicious payload is stored, it is reflected in the page output without escaping, creating a cross‑site scripting vector that compromises the victim’s browser session.
OpenCVE Enrichment