Stored Cross-Site Scripting in Simple Ajax Chat Plugin for WordPress
CVE-2026-2987
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 March 2026
What is CVE-2026-2987?
The Simple Ajax Chat plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability due to inadequate input sanitization and output escaping, specifically through the 'c' parameter in versions up to and including 20260217. This flaw allows unauthenticated attackers to inject arbitrary web scripts into pages, which can execute whenever users access these compromised pages, thus posing a significant risk to site integrity and user safety.
Affected Version(s)
Simple Ajax Chat β Add a Fast, Secure Chat Box 0 <= 20260217