First published: Fri Apr 26 2024(Updated: )
The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
NinjaTeam WP Chat App | <3.6.4 | |
WordPress WP Chat App | <3.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2837 is considered a moderate severity vulnerability due to the potential for Cross-Site Scripting attacks.
To fix CVE-2024-2837, update the WP Chat App plugin to version 3.6.4 or later.
CVE-2024-2837 affects users of the WP Chat App WordPress plugin prior to version 3.6.4.
CVE-2024-2837 is a Cross-Site Scripting vulnerability resulting from inadequate sanitization of plugin settings.
No, CVE-2024-2837 can only be exploited by high privilege users such as admins.