The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 06:17
Updated : 2026-09-03 17:50
NVD link : CVE-2026-81807
Mitre link : CVE-2026-81807
CVE.ORG link : CVE-2026-81807
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
