Sensitive Data Exposure in Simple Ajax Chat by Jeff Starr
CVE-2026-3075

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 February 2026

What is CVE-2026-3075?

The Simple Ajax Chat plugin by Jeff Starr contains a vulnerability that allows unauthorized users to access and retrieve embedded sensitive system information. This issue affects all versions from n/a through <= 20251121, posing a risk to users' private data and overall security. It is crucial for webmasters using this plugin to take immediate action and ensure their systems are secure.

Affected Version(s)

Simple Ajax Chat 0 <= 20251121

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.