Junglewise Threat Intelligence

CVE-2026-12041: Chatra Live Chat + ChatBot + Cart Saver Stored XSS in admin settings

CVE-2026-12041 · Severity: medium · CVSS 4.4 · Published 2026-07-08

Executive brief

The Chatra Live Chat plugin for WordPress, which provides customer support and chatbot features, contains a security flaw that allows administrators to save malicious scripts into the plugin settings. In specific environments like WordPress multi-site networks, this could allow a site administrator to execute unauthorized code that affects other users or the site's overall security. This risk is primarily relevant to organizations running multiple websites from a single WordPress installation.

Technical details

The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress (versions up to 1.0.12) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the admin settings component. An authenticated attacker with administrator-level privileges can inject malicious JavaScript into the plugin's configuration. This vulnerability specifically impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. When other users or administrators visit the settings page or affected frontend pages, the injected script executes in their browser context. The vulnerability is tracked as CWE-79.

Affected products

  • Chatra Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12

Timeline

  • 2026-07-08: disclosed: CVE published by Wordfence/NVD

References