Executive brief
The LiveSmart Video Chat plugin for WordPress, which provides integrated video conferencing capabilities, contains a security flaw that allows users with contributor-level access to embed malicious scripts into website pages. When other users or administrators visit these affected pages, the scripts execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The LiveSmart Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'livesmart_widget' shortcode. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page or post. These scripts are stored on the server and execute in the context of any user's browser who views the compromised page. This vulnerability is tracked as CVE-2026-9644 and has been addressed in subsequent updates.
Affected products
- LiveSmart LiveSmart Video Chat Live Video Chat Up to, and including, 1.2
Timeline
- 2026-05-28: advisory: Initial disclosure by Wordfence and NVD publication.