CVE · Medium

CVE-2026-7795 — Click to Chat – HoliThemes [click-to-chat-for-whatsapp] < 4.40

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7795 Click to Chat – HoliThemes [click-to-chat-for-whatsapp] < 4.40 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.40 4.40 2026-06-05

CVE-2026-7795

A WordPress plugin called Click to Chat – WA Widget has a security flaw in versions 4.38 and earlier, which allows malicious code injection via the [chat] shortcode's 'num' parameter. The issue arises from inadequate protection against user-supplied input when embedding it within JavaScript strings used in HTML event handlers. As a result, an attacker with sufficient privileges can inject arbitrary scripts that will run whenever a user interacts with the WhatsApp chat button generated by the [chat] shortcode.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.