Cross-site Scripting Vulnerability in Click to Chat – WP Support All-in-One Floating Widget by Ninja Team
CVE-2025-31092

6.5MEDIUM

What is CVE-2025-31092?

The Click to Chat – WP Support All-in-One Floating Widget by Ninja Team is susceptible to a Cross-site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or the manipulation of user actions. The vulnerability affects versions up to 2.3.4, making it crucial for users to apply security updates and review their implementation to safeguard against potential exploitation.

Affected Version(s)

Click to Chat – WP Support All-in-One Floating Widget <= 2.3.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.