plugin

Simple Ajax Chat Vulnerabilities

16 known security issues reported for the Simple Ajax Chat WordPress plugin. Most recent disclosed Mar 12, 2026.

2 high 7 medium

Running Simple Ajax Chat on your site? Check whether your installed version is affected.

Scan your site free

Simple Ajax Chat - Unauthenticated Stored Cross-Site Scripting via 'c' vulnerability

high

Unauthenticated Stored Cross-Site Scripting via 'c' vulnerability

CVSS:
7.1
Affected:
up to 20260217
Fixed in:
20260301
Disclosed:
Mar 12, 2026

Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c'

medium

The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exec...

CVSS:
6.1
Affected:
up to 20260217
Fixed in:
20260301
Disclosed:
Mar 12, 2026

CVE-2026-2987 on NVD →

Simple Ajax Chat <= 20251121 - Unauthenticated Information Exposure

medium

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 20251121. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 20251121
Fixed in:
20260217
Disclosed:
Feb 17, 2026

CVE-2026-3075 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20240412

unknown

[en] The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 20240412
Fixed in:
20240412
Disclosed:
Jun 4, 2024

CVE-2024-2470 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box <= 20240318 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240318 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 20240318
Fixed in:
20240412
Disclosed:
May 14, 2024

CVE-2024-2470 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20240223

unknown
Affected:
up to 20240223
Fixed in:
20240223
Disclosed:
Apr 9, 2024

CVE-2024-2957 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20240216

unknown

[en] The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20231101 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...

Affected:
up to 20240216
Fixed in:
20240216
Disclosed:
Mar 27, 2024

CVE-2024-2956 on NVD →

Simple Ajax Chat <= 20240216 - Unauthenticated Stored Cross-Site Scripting

high

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field in all versions up to, and including, 20240216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker to inject arbitrary web s...

CVSS:
7.2
Affected:
up to 20240216
Fixed in:
20240223
Disclosed:
Mar 26, 2024

CVE-2024-1983 on NVD →

Simple Ajax Chat <= 20231101 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20231101 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 20231101
Fixed in:
20240216
Disclosed:
Mar 26, 2024

CVE-2024-2956 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20240223

unknown

[en] The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.

Affected:
up to 20240223
Fixed in:
20240223
Disclosed:
Mar 20, 2024

CVE-2024-1983 on NVD →

Simple Ajax Chat <= 20220115 - Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.

CVSS:
5.4
Affected:
up to 20220115
Fixed in:
20220216
Disclosed:
Apr 15, 2022

CVE-2022-27850 on NVD →

Simple Ajax Chat Plugin <= 20220115 - Sensitive Information Disclosure

medium

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

CVSS:
5.3
Affected:
up to 20220115
Fixed in:
20220216
Disclosed:
Apr 15, 2022

CVE-2022-27849 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20220216

unknown

[en] Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

Affected:
up to 20220216
Fixed in:
20220216
Disclosed:
Apr 15, 2022

CVE-2022-27849 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20220216

unknown

[en] Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.

Affected:
up to 20220216
Fixed in:
20220216
Disclosed:
Apr 15, 2022

CVE-2022-27850 on NVD →

Simple Ajax Chat – Add a Fast, Secure Chat Box [simple-ajax-chat] < 20220216

unknown

[en] Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.

Affected:
up to 20220216
Fixed in:
20220216
Disclosed:
Mar 25, 2022

CVE-2022-25610 on NVD →

Simple Ajax Chat <= 20220115 - Unauthenticated Stored Cross-Site Scripting

medium

The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 20220115 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user ac...

CVSS:
5.4
Affected:
up to 20220115
Fixed in:
20220216
Disclosed:
Feb 16, 2022

CVE-2022-25610 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database