What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.3.
Explanation of Vulnerability in Simple Terms
02Summary
Click to Chat – WP Support All-in-One Floating Widget versions 2.3.3 and earlier contain a code injection vulnerability. An authenticated user with low privileges can inject malicious code by crafting a request that exploits insufficient input validation. The injected code executes in the context of other users' sessions, potentially affecting site data and functionality.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious code that affects other users' sessions and site data.
Potential impact on your site
04Site Impact
Attackers with basic WordPress accounts can compromise admin sessions and modify site content or settings.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account and trick a site admin or higher-privileged user into visiting a malicious link.
Key dates
06Disclosure timeline
October 17, 2024
CVE published
April 28, 2026
Record updated