Junglewise Threat Intelligence

CVE-2026-66636: Wise Chat Contributor cross-site scripting (XSS)

CVE-2026-66636 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Executive brief

Wise Chat is a WordPress plugin that facilitates live chat and communication features on websites. The plugin contains a cross-site scripting (XSS) vulnerability that allows users with Contributor-level access to inject malicious scripts. An attacker could exploit this to steal visitor data, hijack user accounts, or deface website content, though the attack requires user interaction with a malicious link or crafted page.

Technical details

The vulnerability is a stored/contributor cross-site scripting (XSS) flaw in Wise Chat plugin versions up to 3.4.1. It requires Contributor-level privileges to exploit, meaning an attacker must either have legitimate contributor access or compromise an account with such permissions. The attack vector is through user interaction—a privileged user must click a malicious link, visit a crafted page, or submit a specially crafted form. An attacker can inject JavaScript code that executes in the context of visitors' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users. No official patch has been released as of the advisory date; users should update the plugin or request mitigation from their hosting provider.

Affected products

  • Wise Chat Wise Chat <=3.4.1

Timeline

  • 2026-08-18: disclosed: Published by Patchstack
  • 2026-07-09: other: Reported by Ananda Dhakal (Patchstack)

References