Executive brief
The Elfsight WhatsApp Chat CC plugin for WordPress, which allows website owners to integrate WhatsApp messaging for customer support, contains a security flaw. An attacker with basic contributor-level access could inject malicious scripts into the website. If a site visitor or administrator interacts with the affected page, the script could redirect them to malicious sites, display unauthorized advertisements, or steal session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Elfsight WhatsApp Chat CC plugin for WordPress (versions <= 1.2.0) due to improper neutralization of input during web page generation. The vulnerability requires 'Contributor' level privileges to exploit and relies on user interaction (UI:R) from a victim. An attacker can inject malicious JavaScript payloads that execute within the context of the victim's browser session. As of the advisory date, no official patch has been released, and the vulnerability is classified under CWE-79.
Affected products
- Elfsight Elfsight WhatsApp Chat CC <= 1.2.0
Timeline
- 2026-01-27: other: Reported by researcher benzdeus
- 2026-02-26: disclosed: Vulnerability disclosed by Patchstack
- 2026-04-08: advisory: CVE published to NVD