Input validation vulnerability in WP Chat App 3.6.1

The WP Chat App add-on for WordPress can be easily hacked through the add-on’s widget or block feature. This happens because the add-on does not properly clean up or secure certain user-provided information, such as the button color or phone number. This vulnerability allows hackers with contributor or higher access to insert malicious scripts into pages. These scripts will run whenever someone views the affected page.

Detected in:

WP Chat App fixed vulnerable versions: >= * <= 3.6.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.