CVE-2026-18404: Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box
The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consentmessage' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit requires no user interaction beyond page load, as setting autoopen and consentenabled to 'yes' in the injected data-box JSON causes the consent box — and the embedded script — to execute immediately on page load.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with Contributor-level access or higher can exploit it. The attacker must be able to inject a crafted .qlwapp data-box containing the consent_message JSON attribute.
What conditions cause the injected script to run?
The attacker can set auto_open and consent_enabled to "yes" in the injected data-box JSON. This causes the consent box and embedded script to execute when a user loads the affected page, without additional interaction.
Which versions are affected?
All versions of Social Chat – Click To Chat App Button up to and including 8.6.2 are affected.