Stored XSS Vulnerability in Dialogity Free Live Chat by Dialogity
CVE-2025-57912

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-57912?

The Dialogity Free Live Chat software is prone to a stored Cross-Site Scripting (XSS) vulnerability, which can allow malicious users to inject arbitrary web scripts into the pages viewed by other users. This weakness can lead to unauthorized access, data manipulation, and other security issues if exploited. The affected versions of the product range from n/a to 1.0.3, highlighting a significant security concern for web applications utilizing this chat tool.

Affected Version(s)

Dialogity Free Live Chat <= 1.0.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vinit Lakra (Patchstack Alliance)
.