CVE · Medium

CVE-2021-36846 — Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-36846 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.8.5 2.8.5 2022-04-07

CVE-2021-36846

The Chaty plugin before version 2.8.5 fails to properly sanitize and escape certain configuration settings, enabling administrators and other high-privilege users to inject malicious scripts that execute in the browser, bypassing protections that normally prevent unfiltered HTML from being used.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.