Executive brief
Simple Ajax Chat is a popular WordPress plugin that displays user-submitted chat messages on web pages. The plugin fails to properly escape chat messages before rendering them, allowing any unauthenticated visitor to inject malicious JavaScript code. When other users (including site administrators) view the chat, the injected script automatically executes in their browsers, potentially enabling account takeover, data theft, or site compromise.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the Simple Ajax Chat WordPress plugin's chat message linkification feature. The plugin automatically converts URLs in chat messages into hyperlinks but fails to escape HTML attributes, allowing an attacker to break out of the href attribute by injecting a double-quote character followed by malicious HTML attributes and JavaScript event handlers. The attack requires no authentication or special configuration—the attacker can submit a malicious message like "http://a.co/"autofocus/onfocus="alert(document.domain)" through either the web form or a direct POST request using the plugin's hardcoded secondary token. When any visitor (including administrators) loads the page containing the chat, the injected JavaScript automatically executes. The vulnerability is fixed in version 20260827.
Affected products
- Simple Ajax Chat Simple Ajax Chat before 20260827
Timeline
- 2026-08-31: disclosed
- 2026-08-27: patched: Fixed in version 20260827