Stored Cross-Site Scripting in Simple Ajax Chat Plugin for WordPress
CVE-2026-81825
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 September 2026
What is CVE-2026-81825?
The Simple Ajax Chat plugin for WordPress suffers from a vulnerability that allows attackers to perform Stored Cross-Site Scripting due to inadequate sanitization and escaping of chat messages. This vulnerability enables unauthenticated users to inject arbitrary scripts into the chat, which are then stored and executed whenever the chat is accessed by users. The plugin's nonce, intended to secure message submissions, is publicly visible, which further compromises its effectiveness as a protective measure. As a result, malicious actors can submit harmful messages that affect all visitors, posing serious security risks.
Affected Version(s)
Simple Ajax Chat β Add a Fast, Secure Chat Box 0 <= 20260811