Impact
The vulnerability allows a contributor to inject malicious scripts into chat content. Based on the description, it is inferred that contributors can post messages that bypass the plugin's sanitization. Those scripts are rendered unmodified in the browsers of any user that reads the chat, enabling session hijacking, defacement, or credential theft.
Affected Systems
The Marcin Wise Chat WordPress plugin, for all releases up to and including version 3.4, is affected.
Risk and Exploitability
The CVSS score of 6.5 rates the flaw as moderate and the EPSS score is not available; it is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker with the ability to post messages can supply crafted chat content that bypasses the plugin's sanitization. When the content is displayed to any visitor, the embedded script executes in that user's browser context, exposing typical XSS risks.
OpenCVE Enrichment