What the vulnerability does
01Description
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
Explanation of Vulnerability in Simple Terms
The Chaty WordPress plugin through version 2.8.3 contains a stored cross-site scripting (XSS) vulnerability. An authenticated admin can inject malicious scripts through plugin settings that execute in the browsers of site visitors. The vulnerability requires admin privileges and user interaction to exploit, but can affect the site's integrity and visitor security.
What an attacker can do
Inject malicious scripts that run in visitors' browsers when they view the site.
Potential impact on your site
Visitors' browsers can be compromised; their data or sessions may be stolen if an admin account is compromised.
Conditions required to exploit
Admin-level access to the WordPress site; victim must visit an affected page.
Key dates
External resources
Related vulnerabilities