Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected products
Unknown · Simple Ajax Chat