Stored Cross-Site Scripting in Simple Ajax Chat Plugin for WordPress
CVE-2026-81825

7.2HIGH

What is CVE-2026-81825?

The Simple Ajax Chat plugin for WordPress suffers from a vulnerability that allows attackers to perform Stored Cross-Site Scripting due to inadequate sanitization and escaping of chat messages. This vulnerability enables unauthenticated users to inject arbitrary scripts into the chat, which are then stored and executed whenever the chat is accessed by users. The plugin's nonce, intended to secure message submissions, is publicly visible, which further compromises its effectiveness as a protective measure. As a result, malicious actors can submit harmful messages that affect all visitors, posing serious security risks.

Affected Version(s)

Simple Ajax Chat – Add a Fast, Secure Chat Box 0 <= 20260811

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HEI LAI SZE
.