CVE-2021-25016: Chaty < 2.8.3 - Reflected Cross-Site Scripting
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25016?
CVE-2021-25016 is a vulnerability in the Chaty WordPress plugin before version 2.8.3 and Chaty Pro WordPress plugin before version 2.8.2 that allows for Reflected Cross-Site Scripting.
How severe is CVE-2021-25016?
CVE-2021-25016 has a severity rating of 6.1 (medium).
Which software versions are affected by CVE-2021-25016?
The affected software versions are Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2.
How can I fix CVE-2021-25016?
To fix CVE-2021-25016, update the Chaty WordPress plugin to version 2.8.3 or later, and the Chaty Pro WordPress plugin to version 2.8.2 or later.
What is the Common Weakness Enumeration (CWE) for this vulnerability?
The Common Weakness Enumeration (CWE) for CVE-2021-25016 is CWE-79 (Improper Neutralization of Input During Web Page Generation).