Stored Cross-Site Scripting in Social Chat App by WordPress
CVE-2026-18404

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2026

What is CVE-2026-18404?

The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This vulnerability affects all versions up to and including 8.6.2, allowing authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts via the 'consent_message' JSON attribute in the .qlwapp data-box. The exploit can be executed without user interaction, as the crafted consent box β€” enabled by setting auto_open and consent_enabled attributes β€” causes the malicious script to execute immediately upon page load, posing significant risks to users accessing those pages.

Affected Version(s)

Social Chat – Click To Chat App Button 0 <= 8.6.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

suyoung kim(AhnLab)
.