vulnerability

WordPress Plugin: chaty: CVE-2021-25016: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Dec 6, 2021
Added
May 15, 2025
Modified
May 15, 2025

Description

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

Solution

chaty-plugin-cve-2021-25016
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.