Impact
The Floating Chat Widget plugin in WordPress contains a reflected XSS flaw that allows attackers to inject arbitrary JavaScript by manipulating the 's' search parameter. The vulnerability stems from insufficient sanitization and a browser API bug that bypasses server‑side character escaping. When a user follows a crafted link, the malicious script is executed in the victim’s browser, enabling theft of session cookies, defacement, or phishing. The weakness is classified as CWE‑79, denoting improper input validation for output escaping.
Affected Systems
WordPress sites that have the Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin installed in any version up to and including 3.5.9 are vulnerable. The issue is not tied to any particular WordPress core version but to the plugin’s front‑end code.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium‑severity flaw. EPSS is not available, but the publicly disclosed references suggest the exploit is straightforward to craft, relying only on a manipulated URL. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation at the time of reporting. The likely attack vector is a phishing or social‑engineering campaign where users are enticed to click a malicious link embedding a crafted 's' parameter. Without prompt remediation, attackers can gain persistent client‑side access to any visitor of the compromised site.
OpenCVE Enrichment