CVE-2026-73360: WordPress Chaty Pro plugin <= 3.5.8 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Chaty Pro pluginto a version that resolves this vulnerability.Fixed in 3.5.9
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites running Chaty Pro version 3.5.8 or earlier are affected according to the available information. The issue is network-reachable and requires no attacker privileges, but exploitation requires user interaction.
What does an attacker need to exploit this issue?
An attacker does not need an account or other privileges to attempt exploitation. A victim must interact with attacker-supplied content for the XSS payload to execute.
What can be done while a patch is unavailable?
The provided information identifies affected versions through 3.5.8 but does not provide a fixed version or workaround. If patching cannot occur immediately, prioritize reducing opportunities for users to interact with untrusted content associated with the affected plugin.