Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
Update the WordPress collectchat Plugin to the latest available version (at least 2.5.0).