Junglewise Threat Intelligence

CVE-2026-8420: BLOGCHAT Chat System CSRF in WordPress plugin

CVE-2026-8420 · Severity: medium · CVSS 6.1 · Published 2026-05-20

Executive brief

The BLOGCHAT Chat System plugin for WordPress, which adds chat functionality to websites, contains a security flaw that could allow an attacker to change plugin settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify configurations or inject harmful scripts into the site. This could lead to unauthorized site changes or the compromise of visitor data through malicious web scripts.

Technical details

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on several functions within the wp-blogchat-widget.php file. This vulnerability affects all versions up to and including 1.3.6.3. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request to the server. Successful exploitation allows the attacker to update plugin settings and potentially inject malicious web scripts (Stored XSS) into the application. The vulnerability is tracked as CVE-2026-8420 and has a CVSS score of 6.1.

Affected products

  • BLOGCHAT BLOGCHAT Chat System Up to, and including, 1.3.6.3

Timeline

  • 2026-05-20: disclosed: Initial publication of the CVE record.

References