HIGH
specialk
CVE published 2026-09-11
CVE-2026-81825
The Simple Ajax Chat plugin for WordPress has a Stored Cross-Site Scripting vulnerability via Chat Message in all versions up to and including 20260811. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability is caused by insufficient input sanitization and output escaping. The nonce protecting chat message submission is publicly vi [truncated]