CVE Database /
CVE-2021-25016
CVE · Medium
CVE-2021-25016 — Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-25016
|
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.8.3
|
2.8.3 |
2021-12-06 |
—
|
CVE-2021-25016
The Chaty plugin versions before 2.8.3 and Chaty Pro versions before 2.8.2 contain a reflected cross-site scripting vulnerability in the admin dashboard. The flaw exists because the search parameter is not properly sanitized or escaped before being displayed back to users. An attacker could exploit this vulnerability by crafting a malicious link containing JavaScript code in the search parameter.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings