Executive brief
The collectchat plugin for WordPress, which provides interactive chatbot functionality for websites, is vulnerable to a security flaw that allows attackers to inject malicious scripts. If a site administrator or visitor interacts with a specially crafted link or page, an attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website defacement. This issue affects all versions up to 2.4.9 and can be resolved by updating to version 2.5.0.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the collectchat plugin for WordPress (versions <= 2.4.9) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim with active session privileges to interact with a malicious link or visit a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or redirection to malicious sites. The vulnerability is addressed in version 2.5.0.
Affected products
- collectchat collectchat <= 2.4.9
Timeline
- 2026-03-02: other: Reported by researcher Ritsuy
- 2026-04-21: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: NVD publication date
- 2026-04-21: patched: Patch released in version 2.5.0