Ninjateam

Wp Chat App

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 16.11.2024 04:15:04
  • Zuletzt bearbeitet 18.11.2024 17:11:17

The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up to, and including, 3.6.8. This makes it possible for authenticated attac...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 27.06.2024 06:15:13
  • Zuletzt bearbeitet 21.11.2024 09:43:19

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 26.04.2024 05:15:50
  • Zuletzt bearbeitet 14.04.2025 14:20:24

The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

  • EPSS 0.2%
  • Veröffentlicht 09.04.2024 19:15:35
  • Zuletzt bearbeitet 27.02.2025 14:54:18

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. T...

  • EPSS 0.17%
  • Veröffentlicht 07.03.2024 05:15:54
  • Zuletzt bearbeitet 21.01.2025 16:53:47

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes such as...

  • EPSS 0.06%
  • Veröffentlicht 12.02.2024 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:58

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from n/a through 3.4.4.