Junglewise Threat Intelligence

CVE-2026-7795: HoliThemes Click to Chat , WA Widget Stored XSS in [chat] shortcode

CVE-2026-7795 · Severity: medium · CVSS 6.4 · Published 2026-06-06

Executive brief

The Click to Chat – WA Widget plugin for WordPress, which allows website visitors to contact owners via WhatsApp, contains a security flaw. An attacker with contributor-level access can inject malicious scripts into the website. These scripts execute in the browser of any user who clicks the WhatsApp chat button, potentially leading to unauthorized actions or data theft.

Technical details

The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient escaping of the 'num' parameter within the [chat] shortcode. The CCW_Shortcode::shortcode() function uses esc_attr(), which converts single quotes to HTML entities; however, these entities are then placed inside a JavaScript window.open() call within an HTML onclick attribute. Because browsers decode HTML entities in event handlers before executing JavaScript, an attacker can break out of the string literal and execute arbitrary code. This requires Contributor-level permissions or higher to exploit. The issue is addressed in version 4.39.

Affected products

  • HoliThemes Click to Chat – WA Widget up to, and including, 4.38

Timeline

  • 2026-06-06: disclosed: Initial publication of the CVE record

References