Description
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the <title> element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Floating Chat Widget plugin in WordPress contains a reflected XSS flaw that allows attackers to inject arbitrary JavaScript by manipulating the 's' search parameter. The vulnerability stems from insufficient sanitization and a browser API bug that bypasses server‑side character escaping. When a user follows a crafted link, the malicious script is executed in the victim’s browser, enabling theft of session cookies, defacement, or phishing. The weakness is classified as CWE‑79, denoting improper input validation for output escaping.

Affected Systems

WordPress sites that have the Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin installed in any version up to and including 3.5.9 are vulnerable. The issue is not tied to any particular WordPress core version but to the plugin’s front‑end code.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium‑severity flaw. EPSS is not available, but the publicly disclosed references suggest the exploit is straightforward to craft, relying only on a manipulated URL. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of reporting. The likely attack vector is a phishing or social‑engineering campaign where users are enticed to click a malicious link embedding a crafted 's' parameter. Without prompt remediation, attackers can gain persistent client‑side access to any visitor of the compromised site.

Generated by OpenCVE AI on September 11, 2026 at 05:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Floating Chat Widget plugin to version 3.6.0 or newer to obtain the XSS fix.
  • If an update is not immediately possible, disable the Chaty plugin or remove the widget from public pages to eliminate the vulnerable code path.
  • Apply a custom filter to sanitize the 's' query parameter, ensuring any special characters are encoded before being inserted into HTML attributes or DOM elements.

Generated by OpenCVE AI on September 11, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Premio
Premio floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, Wechat, Email, Sms, Call Button – Chaty
Wordpress
Wordpress wordpress
Vendors & Products Premio
Premio floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, Wechat, Email, Sms, Call Button – Chaty
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the &lt;title&gt; element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value.
Title Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Premio Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, Wechat, Email, Sms, Call Button – Chaty
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T13:46:23.554Z

Reserved: 2026-08-05T15:07:52.166Z

Link: CVE-2026-18964

cve-icon Vulnrichment

Updated: 2026-09-11T13:38:58.438Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:24.760

Modified: 2026-09-11T14:17:25.683

Link: CVE-2026-18964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')