PT-2025-7614 · Unknown · Notfound Chaty Pro
Luc
·
Published
2025-02-22
·
Updated
2025-05-05
·
CVE-2025-26776
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chaty Pro versions n/a through 3.3.3
Description
The issue affects Chaty Pro, allowing an attacker to upload malicious files that can be used to take control of a website. This is due to an Unrestricted Upload of File with Dangerous Type vulnerability, which enables the upload of a web shell to a web server. Thousands of WordPress sites are exposed to takeover. The estimated number of potentially affected devices worldwide is over 18,000 users.
Recommendations
For Chaty Pro versions n/a through 3.3.3, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to the plugin to minimize the risk of takeover. Avoid using the plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notfound Chaty Pro