Stored Cross-Site Scripting in Wise Chat Plugin for WordPress
CVE-2025-3774

7.2HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 June 2025

What is CVE-2025-3774?

The Wise Chat plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping. This flaw, found in all versions up to and including 3.3.4, enables unauthorized attackers to inject malicious web scripts into pages. When users visit these compromised pages, the scripts execute, putting their data and security at risk. Given the reliance on the X-Forwarded-For header, it is essential for users and site administrators to take immediate action to secure their installations.

Affected Version(s)

Wise Chat * <= 3.3.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent Fourcade
.
CVE-2025-3774 : Stored Cross-Site Scripting in Wise Chat Plugin for WordPress