Impact
The Simple Ajax Chat plugin for WordPress contains a stored cross‑site scripting flaw that allows unauthenticated users to inject arbitrary scripts into chat messages. Because the input is not sanitized and also not properly escaped, an attacker can embed JavaScript that will run for every visitor who views a page containing the chat widget. The nonce used to guard message submission is visible on the public chat page, making it ineffective and allowing fully unauthenticated submissions. The flaw is a typical instance of CWE‑79 and represents a significant risk of client‑side compromise.
Affected Systems
All WordPress sites that have installed Simple Ajax Chat – Add a Fast, Secure Chat Box up to and including version 20260811 are affected. The vulnerability is present in every deployment of the plugin where the chat widget is active, regardless of site configuration or theme.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity of a stored XSS vulnerability. With no EPSS data available and the vulnerability not listed in CISA KEV, the likelihood of exploitation is uncertain but non‑zero. The attack vector is purely web‑based: anyone who can submit a chat message can insert malicious code. Because the payload is stored persistently, every subsequent visitor to any page that includes the chat area will execute the injected scripts, potentially stealing cookies, session data, or performing phishing or other client‑side attacks. The attack does not require system privileges or authentication, so the threat surface is broad.
OpenCVE Enrichment