Junglewise Threat Intelligence

CVE-2026-9644: LiveSmart Video Chat Stored XSS in livesmart_widget shortcode

CVE-2026-9644 · Severity: medium · CVSS 6.4 · Published 2026-05-28

Executive brief

The LiveSmart Video Chat plugin for WordPress, which provides integrated video conferencing capabilities, contains a security flaw that allows users with contributor-level access to embed malicious scripts into website pages. When other users or administrators visit these affected pages, the scripts execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The LiveSmart Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'livesmart_widget' shortcode. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into a page or post. These scripts are stored on the server and execute in the context of any user's browser who views the compromised page. This vulnerability is tracked as CVE-2026-9644 and has been addressed in subsequent updates.

Affected products

  • LiveSmart LiveSmart Video Chat Live Video Chat Up to, and including, 1.2

Timeline

  • 2026-05-28: advisory: Initial disclosure by Wordfence and NVD publication.

References