Cross-site Scripting Vulnerability in Click to Chat – WP Support All-in-One Floating Widget by Ninja Team
CVE-2025-31092
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 March 2025
What is CVE-2025-31092?
The Click to Chat – WP Support All-in-One Floating Widget by Ninja Team is susceptible to a Cross-site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or the manipulation of user actions. The vulnerability affects versions up to 2.3.4, making it crucial for users to apply security updates and review their implementation to safeguard against potential exploitation.
Affected Version(s)
Click to Chat – WP Support All-in-One Floating Widget <= 2.3.4