Description
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce protecting chat message submission is publicly visible on the chat page, rendering it ineffective as an authentication barrier and allowing fully unauthenticated attackers to submit malicious messages that are stored persistently and rendered to all visitors on every page load.
Published: 2026-09-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Execution of Arbitrary JavaScript
Action: Apply Patch
AI Analysis

Impact

The Simple Ajax Chat plugin for WordPress contains a stored cross‑site scripting flaw that allows unauthenticated users to inject arbitrary scripts into chat messages. Because the input is not sanitized and also not properly escaped, an attacker can embed JavaScript that will run for every visitor who views a page containing the chat widget. The nonce used to guard message submission is visible on the public chat page, making it ineffective and allowing fully unauthenticated submissions. The flaw is a typical instance of CWE‑79 and represents a significant risk of client‑side compromise.

Affected Systems

All WordPress sites that have installed Simple Ajax Chat – Add a Fast, Secure Chat Box up to and including version 20260811 are affected. The vulnerability is present in every deployment of the plugin where the chat widget is active, regardless of site configuration or theme.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity of a stored XSS vulnerability. With no EPSS data available and the vulnerability not listed in CISA KEV, the likelihood of exploitation is uncertain but non‑zero. The attack vector is purely web‑based: anyone who can submit a chat message can insert malicious code. Because the payload is stored persistently, every subsequent visitor to any page that includes the chat area will execute the injected scripts, potentially stealing cookies, session data, or performing phishing or other client‑side attacks. The attack does not require system privileges or authentication, so the threat surface is broad.

Generated by OpenCVE AI on September 11, 2026 at 05:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Simple Ajax Chat plugin to the latest version that removes the XSS vulnerability.
  • If an update cannot be applied immediately, temporarily disable or uninstall the chat plugin until a patched release is available.
  • Configure a web application firewall to block or strip script tags from content posted through the chat message field, preventing the storage of malicious scripts until the plugin can be updated.

Generated by OpenCVE AI on September 11, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Specialk
Specialk simple Ajax Chat – Add A Fast, Secure Chat Box
Wordpress
Wordpress wordpress
Vendors & Products Specialk
Specialk simple Ajax Chat – Add A Fast, Secure Chat Box
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce protecting chat message submission is publicly visible on the chat page, rendering it ineffective as an authentication barrier and allowing fully unauthenticated attackers to submit malicious messages that are stored persistently and rendered to all visitors on every page load.
Title Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Specialk Simple Ajax Chat – Add A Fast, Secure Chat Box
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:30:53.550Z

Reserved: 2026-08-27T13:32:01.254Z

Link: CVE-2026-81825

cve-icon Vulnrichment

Updated: 2026-09-11T16:34:25.362Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:58.947

Modified: 2026-09-11T21:17:19.997

Link: CVE-2026-81825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')