CVE · Medium

CVE-2021-25016 — Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25016 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.8.3 2.8.3 2021-12-06

CVE-2021-25016

The Chaty plugin versions before 2.8.3 and Chaty Pro versions before 2.8.2 contain a reflected cross-site scripting vulnerability in the admin dashboard. The flaw exists because the search parameter is not properly sanitized or escaped before being displayed back to users. An attacker could exploit this vulnerability by crafting a malicious link containing JavaScript code in the search parameter.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.