Stored Cross-Site Scripting in Wise Chat Plugin for WordPress
CVE-2025-3774
What is CVE-2025-3774?
The Wise Chat plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping. This flaw, found in all versions up to and including 3.3.4, enables unauthorized attackers to inject malicious web scripts into pages. When users visit these compromised pages, the scripts execute, putting their data and security at risk. Given the reliance on the X-Forwarded-For header, it is essential for users and site administrators to take immediate action to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wise Chat * <= 3.3.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved