7.1
CVE-2024-1983
- EPSS 0.16%
- Published 20.03.2024 05:15:45
- Last modified 05.05.2025 18:38:46
- Source contact@wpscan.com
- CVE-Watchlists
- Open
Simple Ajax Chat <= 20240216 - Unauthenticated Stored Cross-Site Scripting
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
Mögliche Gegenmaßnahme
Simple Ajax Chat – Add a Fast, Secure Chat Box: Update to version 20240223, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Product
Simple Ajax Chat – Add a Fast, Secure Chat Box
Version
* - 20240216
Data is provided by the National Vulnerability Database (NVD)
Plugin-planet ≫ Simple Ajax Chat SwPlatformwordpress Version < 20240223
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.37 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.1 | 2.8 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
|