CVE-2025-1450: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1450?
CVE-2025-1450 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2025-1450?
To fix CVE-2025-1450, update the Chaty plugin to version 3.3.6 or later.
Which versions of Chaty are affected by CVE-2025-1450?
CVE-2025-1450 affects all versions of the Chaty plugin up to and including version 3.3.5.
What are the potential impacts of CVE-2025-1450?
The potential impact of CVE-2025-1450 includes allowing attackers to execute arbitrary JavaScript in users' browsers.
Is user data at risk due to CVE-2025-1450?
Yes, user data may be at risk due to stored cross-site scripting vulnerabilities in CVE-2025-1450.