Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 - Unauthenticated Information Exposure
medium
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1. This makes it possible for unauthenticated attackers to extract sensitive user or configu...
- CVSS:
- 5.3
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Feb 24, 2026
CVE-2026-27370 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output es...
- CVSS:
- 6.4
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.6
- Disclosed:
- Feb 26, 2025
CVE-2025-1450 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.2.3
unknown
[en] The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the...
- Affected:
- up to 3.2.3
- Fixed in:
- 3.2.3
- Disclosed:
- Jun 13, 2024
CVE-2024-4149 on NVD →
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 4.4
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.3
- Disclosed:
- May 23, 2024
CVE-2024-4149 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.9
unknown
[en] The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the...
- Affected:
- up to 3.1.9
- Fixed in:
- 3.1.9
- Disclosed:
- Apr 24, 2024
CVE-2024-2972 on NVD →
Floating Chat Widget <= 3.1.8 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cht_social_Whatsapp[bg_color] parameter in all versions up to, and including, 3.1.8 due to insufficient input sanitizat...
- CVSS:
- 5.5
- Affected:
- up to 3.1.8
- Fixed in:
- 3.1.9
- Disclosed:
- Apr 3, 2024
CVE-2024-2972 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Chaty plugin <= 3.1.2 versions.
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.3
- Disclosed:
- Nov 22, 2023
CVE-2023-47759 on NVD →
Chaty <= 3.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 4.4
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.3
- Disclosed:
- Nov 13, 2023
CVE-2023-47759 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <= 3.0.9 versions
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Aug 30, 2023
CVE-2023-25019 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.2
unknown
[en] The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 17, 2023
CVE-2023-3245 on NVD →
Floating Chat Widget - Chaty <= 3.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Floating Chat Widget - Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Jun 26, 2023
CVE-2023-3245 on NVD →
Chaty <= 3.0.9 - Reflected Cross-Site Scripting
medium
The Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'channel' parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...
- CVSS:
- 6.1
- Affected:
- up to 3.0.9
- Fixed in:
- 3.1
- Disclosed:
- May 16, 2023
CVE-2023-25019 on NVD →
Chaty <= 3.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...
- CVSS:
- 4.4
- Affected:
- up to 3.0.9
- Fixed in:
- 3.1
- Disclosed:
- May 16, 2023
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1
unknown
The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- May 16, 2023
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.0.3
unknown
[en] The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Dec 5, 2022
CVE-2022-3858 on NVD →
Floating Chat Widget - Chaty <= 3.0.2 - Authenticated (Administrator+) SQL Injection
high
The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the $chaty_leads parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level privileges or higher...
- CVSS:
- 7.2
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Nov 14, 2022
CVE-2022-3858 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.5
unknown
[en] Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 11, 2022
CVE-2021-36846 on NVD →
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.3 - Admin+ Stored Cross-Site Scripting
medium
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
- CVSS:
- 4.8
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 7, 2022
CVE-2021-36846 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3
unknown
[en] The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- Jan 3, 2022
CVE-2021-25016 on NVD →
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button - Chaty <= 2.8.2 Reflected Cross-Site Scripting
medium
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.3
- Disclosed:
- Dec 6, 2021
CVE-2021-25016 on NVD →
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1
unknown
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.1
- Fixed in:
- 3.1
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.3.6
unknown
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.6
CVE-2025-1450 on NVD →