← WordPress Vulnerabilities
WordPress security by component

Chaty

Chaty is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Mar 05, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: chaty

CVE-2026-27370: Chaty: A security weakness

Chaty is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedMar 05, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 05, 2026 CVE-2026-27370
Chaty: A security weakness
Chaty is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Feb 27, 2025 CVE-2025-1450
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty: Cross-site scripting
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Nov 22, 2023 CVE-2023-47759
Chaty: Cross-site scripting
Chaty is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Aug 30, 2023 CVE-2023-25019
Chaty: Cross-site scripting
Chaty is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 17, 2023 CVE-2023-3245
Floating Chat Widget: Cross-site scripting
Floating Chat Widget is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Dec 05, 2022 CVE-2022-3858
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button: SQL injection
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Apr 11, 2022 CVE-2021-36846
Chaty: Cross-site scripting
Chaty is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jan 03, 2022 CVE-2021-25016
Chaty: Cross-site scripting
Chaty is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1