CVE-2026-81807 PUBLISHED

Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Linkification

Assigner: WPScan
Reserved: 27.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators.

Product Status

Vendor Unknown
Product Simple Ajax Chat
Versions Default: unaffected
  • affected from 0 to 20260827 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE