plugin

Chaty Vulnerabilities

22 known security issues reported for the Chaty WordPress plugin. Most recent disclosed Feb 24, 2026.

1 high 10 medium

Running Chaty on your site? Check whether your installed version is affected.

Scan your site free

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 - Unauthenticated Information Exposure

medium

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1. This makes it possible for unauthenticated attackers to extract sensitive user or configu...

CVSS:
5.3
Affected:
up to 3.5.1
Fixed in:
3.5.2
Disclosed:
Feb 24, 2026

CVE-2026-27370 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output es...

CVSS:
6.4
Affected:
up to 3.3.5
Fixed in:
3.3.6
Disclosed:
Feb 26, 2025

CVE-2025-1450 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.2.3

unknown

[en] The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the...

Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Jun 13, 2024

CVE-2024-4149 on NVD →

Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This...

CVSS:
4.4
Affected:
up to 3.2.2
Fixed in:
3.2.3
Disclosed:
May 23, 2024

CVE-2024-4149 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.9

unknown

[en] The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the...

Affected:
up to 3.1.9
Fixed in:
3.1.9
Disclosed:
Apr 24, 2024

CVE-2024-2972 on NVD →

Floating Chat Widget <= 3.1.8 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cht_social_Whatsapp[bg_color] parameter in all versions up to, and including, 3.1.8 due to insufficient input sanitizat...

CVSS:
5.5
Affected:
up to 3.1.8
Fixed in:
3.1.9
Disclosed:
Apr 3, 2024

CVE-2024-2972 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Chaty plugin <= 3.1.2 versions.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Nov 22, 2023

CVE-2023-47759 on NVD →

Chaty <= 3.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it...

CVSS:
4.4
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Nov 13, 2023

CVE-2023-47759 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premio Chaty plugin <= 3.0.9 versions

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
Aug 30, 2023

CVE-2023-25019 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1.2

unknown

[en] The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jul 17, 2023

CVE-2023-3245 on NVD →

Floating Chat Widget - Chaty <= 3.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Floating Chat Widget - Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Jun 26, 2023

CVE-2023-3245 on NVD →

Chaty <= 3.0.9 - Reflected Cross-Site Scripting

medium

The Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'channel' parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute...

CVSS:
6.1
Affected:
up to 3.0.9
Fixed in:
3.1
Disclosed:
May 16, 2023

CVE-2023-25019 on NVD →

Chaty <= 3.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

CVSS:
4.4
Affected:
up to 3.0.9
Fixed in:
3.1
Disclosed:
May 16, 2023

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1

unknown

The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a...

Affected:
up to 3.1
Fixed in:
3.1
Disclosed:
May 16, 2023

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.0.3

unknown

[en] The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Dec 5, 2022

CVE-2022-3858 on NVD →

Floating Chat Widget - Chaty <= 3.0.2 - Authenticated (Administrator+) SQL Injection

high

The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the $chaty_leads parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level privileges or higher...

CVSS:
7.2
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Nov 14, 2022

CVE-2022-3858 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.5

unknown

[en] Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3

Affected:
up to 2.8.5
Fixed in:
2.8.5
Disclosed:
Apr 11, 2022

CVE-2021-36846 on NVD →

Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.3 - Admin+ Stored Cross-Site Scripting

medium

Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3

CVSS:
4.8
Affected:
up to 2.8.3
Fixed in:
2.8.5
Disclosed:
Apr 7, 2022

CVE-2021-36846 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 2.8.3

unknown

[en] The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Jan 3, 2022

CVE-2021-25016 on NVD →

Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button - Chaty <= 2.8.2 Reflected Cross-Site Scripting

medium

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Dec 6, 2021

CVE-2021-25016 on NVD →

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.1

unknown

The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.1
Fixed in:
3.1

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.3.6

unknown
Affected:
up to 3.3.6
Fixed in:
3.3.6

CVE-2025-1450 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database