plugin

Chaty Pro Vulnerabilities

2 known security issues reported for the Chaty Pro WordPress plugin. Most recent disclosed Jul 27, 2026.

1 critical 1 medium

Running Chaty Pro on your site? Check whether your installed version is affected.

Scan your site free

Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter

medium

The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the...

CVSS:
6.5
Affected:
up to 3.5.5
Fixed in:
3.5.6
Disclosed:
Jul 27, 2026

CVE-2026-6251 on NVD →

Chaty Pro <= 3.3.3 - Unauthenticated Arbitrary File Upload

critical

The Chaty Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 3.3.3
Fixed in:
3.3.4
Disclosed:
Feb 14, 2025

CVE-2025-26776 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database