Stored Cross-Site Scripting in Social Chat App by WordPress
CVE-2026-18404
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-18404?
The Social Chat β Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This vulnerability affects all versions up to and including 8.6.2, allowing authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts via the 'consent_message' JSON attribute in the .qlwapp data-box. The exploit can be executed without user interaction, as the crafted consent box β enabled by setting auto_open and consent_enabled attributes β causes the malicious script to execute immediately upon page load, posing significant risks to users accessing those pages.
Affected Version(s)
Social Chat β Click To Chat App Button 0 <= 8.6.2