PT-2024-18471 · WordPress · Simple Ajax Chat

Fourcade

·

Published

2024-03-19

·

Updated

2025-05-05

·

CVE-2024-1983

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The Simple Ajax Chat WordPress plugin versions prior to 20240223
Description The issue concerns the reflection of unsanitized input to other users, specifically when visitors use malicious names in the chat. This allows for potential malicious activity.
Recommendations For versions prior to 20240223, update to version 20240223 or later to resolve the issue. As a temporary workaround, consider restricting user input for names in the chat to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2024-1983

Affected Products

Simple Ajax Chat