CVE-2024-2956: Simple Ajax Chat <= 20231101 - Authenticated (Admin+) Stored Cross-Site Scripting
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20231101 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2956?
CVE-2024-2956 has a medium severity due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2956?
To fix CVE-2024-2956, update the Simple Ajax Chat plugin to a version released after 20231101 that includes the necessary input sanitization and output escaping.
Who is affected by CVE-2024-2956?
CVE-2024-2956 affects all versions of the Simple Ajax Chat plugin for WordPress up to and including version 20231101.
What type of attack can exploit CVE-2024-2956?
CVE-2024-2956 can be exploited through Stored Cross-Site Scripting attacks by authenticated users.
Is user authentication required to exploit CVE-2024-2956?
Yes, exploitation of CVE-2024-2956 requires the attacker to be an authenticated user.