Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Unknown · Simple Ajax Chatpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/7aceefd5-aa09-4828-b375-6a62997fa0c2/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.