plugin

Click To Chat For Whatsapp Vulnerabilities

7 known security issues reported for the Click To Chat For Whatsapp WordPress plugin. Most recent disclosed Jun 5, 2026.

1 high 3 medium

Running Click To Chat For Whatsapp on your site? Check whether your installed version is affected.

Scan your site free

Click to Chat <= 4.39 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'num' Shortcode Parameter

medium

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to insufficient escaping when embedding user-supplied shortcode attribute values inside JavaScript string literals that are the...

CVSS:
6.4
Affected:
up to 4.39
Fixed in:
4.40
Disclosed:
Jun 5, 2026

CVE-2026-7795 on NVD →

Click to Chat <= 4.22 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via data-no_number Parameter

medium

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject...

CVSS:
6.4
Affected:
up to 4.22
Fixed in:
4.23
Disclosed:
Jun 13, 2025

CVE-2025-5336 on NVD →

Click to Chat &#8211; HoliThemes [click-to-chat-for-whatsapp] < 4.0

unknown

[en] The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in...

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
May 2, 2024

CVE-2024-3849 on NVD →

Click to Chat – HoliThemes <= 3.35 - Authenticated (Contributor+) Local File Inclusion

high

The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it possible for authenticated attackers, with contributor access or above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in thos...

CVSS:
8.8
Affected:
up to 3.35
Fixed in:
4.0
Disclosed:
Apr 17, 2024

CVE-2024-3849 on NVD →

Click to Chat &#8211; HoliThemes [click-to-chat-for-whatsapp] < 3.18.1

unknown

[en] The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as a...

Affected:
up to 3.18.1
Fixed in:
3.18.1
Disclosed:
Jan 16, 2023

CVE-2022-4480 on NVD →

Click to Chat <= 3.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 3.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 3.18
Fixed in:
3.18.1
Disclosed:
Dec 21, 2022

CVE-2022-4480 on NVD →

Click to Chat &#8211; HoliThemes [click-to-chat-for-whatsapp] < 4.23

unknown
Affected:
up to 4.23
Fixed in:
4.23

CVE-2025-5336 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database