Executive brief
The Chatra Live Chat plugin for WordPress, which provides customer support and chatbot features, contains a security flaw that allows administrators to save malicious scripts into the plugin settings. In specific environments like WordPress multi-site networks, this could allow a site administrator to execute unauthorized code that affects other users or the site's overall security. This risk is primarily relevant to organizations running multiple websites from a single WordPress installation.
Technical details
The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress (versions up to 1.0.12) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the admin settings component. An authenticated attacker with administrator-level privileges can inject malicious JavaScript into the plugin's configuration. This vulnerability specifically impacts WordPress multi-site installations or environments where the 'unfiltered_html' capability has been disabled for administrators. When other users or administrators visit the settings page or affected frontend pages, the injected script executes in their browser context. The vulnerability is tracked as CWE-79.
Affected products
- Chatra Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12
Timeline
- 2026-07-08: disclosed: CVE published by Wordfence/NVD