Impact
The vulnerability is a stored cross‑site scripting flaw in the Social Chat – Click To Chat App Button WordPress plugin. The attacker, required to have contributor level or higher, can inject a malicious JSON payload into the plugin’s data‑box configuration, specifically the 'consent_message' attribute. Because the plugin renders this JSON without proper sanitization or escaping, the injected script is executed automatically when any user visits a page that contains the data‑box. This flaw can be used to steal credentials, deface the site, hijack user sessions, or any other malicious activity that results from arbitrary JavaScript execution on a visitor’s browser.
Affected Systems
All installations of the Social Chat – Click To Chat App Button plugin version 8.6.2 or earlier, including all earlier releases, are affected. The plugin is packaged by quadlayers and distributed through the WordPress plugin repository.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. Because the exploit requires only authenticated access at contributor level and no further user interaction beyond a normal page load, the risk is significant for sites that grant contributors or higher permissions. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, but the impact is broad, affecting all visitors to the compromised page. Once a malicious script is injected via the data‑box, it will execute for every user who loads the affected page, giving the attacker persistent access to arbitrary code execution within the site context.
OpenCVE Enrichment