plugin

Collectchat Vulnerabilities

5 known security issues reported for the Collectchat WordPress plugin. Most recent disclosed Apr 21, 2026.

1 high 4 medium

Running Collectchat on your site? Check whether your installed version is affected.

Scan your site free

Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.9 - Unauthenticated Stored Cross-Site Scripting

high

The Chatbot for WordPress by Collect.chat ⚡️ plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exec...

CVSS:
7.2
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Apr 21, 2026

CVE-2026-40765 on NVD →

Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field

medium

The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Feb 13, 2026

CVE-2026-0736 on NVD →

Chatbot for WordPress by Collect.chat ⚡️ <= 2.4.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Chatbot for WordPress by Collect.chat ⚡️ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissi...

CVSS:
4.4
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jul 15, 2024

CVE-2024-6498 on NVD →

collectchat <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The collectchat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Mar 28, 2024

CVE-2024-30436 on NVD →

Chatbot for WordPress <= 2.3.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts...

CVSS:
4.4
Affected:
2.3.9 – 2.3.9
Fixed in:
2.4.0
Disclosed:
Nov 24, 2023

CVE-2023-5691 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database