Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.9 - Unauthenticated Stored Cross-Site Scripting
high
The Chatbot for WordPress by Collect.chat ⚡️ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exec...
- CVSS:
- 7.2
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 21, 2026
CVE-2026-40765 on NVD →
Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field
medium
The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Feb 13, 2026
CVE-2026-0736 on NVD →
Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Chatbot for WordPress by Collect.chat ⚡️ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...
- CVSS:
- 4.4
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Jul 15, 2024
CVE-2024-6498 on NVD →
collectchat <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The collectchat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.2
- Disclosed:
- Mar 28, 2024
CVE-2024-30436 on NVD →
Chatbot for WordPress <= 2.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- 2.3.9 – 2.3.9
- Fixed in:
- 2.4.0
- Disclosed:
- Nov 24, 2023
CVE-2023-5691 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database