Junglewise Threat Intelligence

CVE-2026-15759: themeatelier ChatHelp Stored XSS in Shortcode Attributes

CVE-2026-15759 · Severity: medium · CVSS 6.4 · Published 2026-07-17

Executive brief

The ChatHelp plugin for WordPress, which adds chat buttons and WooCommerce order features to websites, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The ChatHelp WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'number' and 'group' shortcode attributes. This vulnerability exists in versions up to and including 3.5.1. An authenticated attacker with contributor-level permissions or higher can exploit this by embedding malicious web scripts into a page via shortcodes. These scripts are then stored and executed in the context of any user's browser who visits the compromised page. The issue is tracked as CWE-79 and has been addressed in subsequent updates.

Affected products

  • themeatelier ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form up to, and including, 3.5.1

Timeline

  • 2026-07-17: advisory: NVD publication date
  • 2026-07-17: disclosed: Wordfence advisory published

References