Wise Chat <= 3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...
- CVSS:
- 6.4
- Affected:
- up to 3.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-66636 on NVD →
Wise Chat <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
high
The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e...
- CVSS:
- 7.2
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.5
- Disclosed:
- Jun 16, 2025
CVE-2025-3774 on NVD →
Wise Chat [wise-chat] < 3.3.4
unknown
[en] The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file at...
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- May 17, 2025
CVE-2024-13613 on NVD →
Wise Chat <= 3.3.3 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
high
The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain file attachm...
- CVSS:
- 7.5
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.4
- Disclosed:
- May 16, 2025
CVE-2024-13613 on NVD →
Wise Chat [wise-chat] < 3.1.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Kainex Wise Chat.This issue affects Wise Chat: from n/a through 3.1.3.
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Nov 18, 2023
CVE-2023-32504 on NVD →
Wise Chat <= 3.1.3 - Cross-Site Request Forgery
medium
The Wise Chat plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing nonce validation on several functions such as resetAnonymousCounterAction, resetSettingsAction, deleteAllUsersAndMessagesAction, deleteBanAction, addBanAction, clearChannelActio...
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- May 9, 2023
CVE-2023-32504 on NVD →
Wise Chat <= 2.8.3 - CSV Injection
medium
The Wise Chat plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configurati...
- CVSS:
- 5.5
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Jul 9, 2020
Wise Chat [wise-chat] < 2.8.4
unknown
CSV Injection vulnerability found by Vishnupriya Ilango (Fortinet's FortiGuard Labs) in WordPress Wise Chat plugin (versions <= 2.8.3).
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Jul 9, 2020
Wise Chat [wise-chat] < 2.8.4
unknown
The Wise Chat plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configurati...
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
- Disclosed:
- Jul 9, 2020
Wise Chat <= 2.6.3 - Reverse Tabnabbing
medium
The Wise Chat plugin for WordPress is vulnerable to Reverse Tabnabbing in versions up to, and including, 2.6.3. This is due to mishandling of external links due to omitting noopener and noreferrer. This makes it possible for a chat-using attacker to provide a link that opens a new tab while silently redirecting the ori...
- CVSS:
- 6.1
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Jan 25, 2019
CVE-2019-6780 on NVD →
Wise Chat [wise-chat] < 2.7
unknown
[en] The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.
- Affected:
- up to 2.7
- Fixed in:
- 2.7
- Disclosed:
- Jan 24, 2019
CVE-2019-6780 on NVD →
Wise Chat [wise-chat] < 2.8.4
unknown
It could allow an unauthenticated or low privileges user to inject a command in chat messages that will be included in the exported CSV file (via message backup), leading to possible code execution.
- Affected:
- up to 2.8.4
- Fixed in:
- 2.8.4
Wise Chat [wise-chat] < 3.3.5
unknown
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.5
CVE-2025-3774 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database