First published: Thu Mar 27 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget allows Stored XSS. This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through 2.3.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ninja Team Click to Chat – WP Support All-in-One Floating Widget | <=2.3.4 | |
NinjaTeam Click to Chat – WP Support All-in-One Floating Widget | <=2.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31092 is a Stored Cross-site Scripting (XSS) vulnerability which can lead to data exposure and unauthorized actions on behalf of users.
To fix CVE-2025-31092, update the Click to Chat – WP Support All-in-One Floating Widget plugin to version 2.3.5 or later.
CVE-2025-31092 affects users of the Click to Chat – WP Support All-in-One Floating Widget plugin versions up to and including 2.3.4.
CVE-2025-31092 exploits improper neutralization of input during web page generation, leading to potential security breaches via stored XSS.
Yes, CVE-2025-31092 can be easily exploited by attackers to execute scripts in the context of affected users' sessions.