Stored Cross-Site Scripting in Wise Chat Plugin for WordPress
CVE-2025-3774
7.2HIGH
What is CVE-2025-3774?
The Wise Chat plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping. This flaw, found in all versions up to and including 3.3.4, enables unauthorized attackers to inject malicious web scripts into pages. When users visit these compromised pages, the scripts execute, putting their data and security at risk. Given the reliance on the X-Forwarded-For header, it is essential for users and site administrators to take immediate action to secure their installations.
Affected Version(s)
Wise Chat * <= 3.3.4