Vulnerability Description
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Premio | Chaty | < 2.8.3 |
| Premio | Chaty Pro | < 2.8.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/b5035987-6227-4fc6-bc45-1e8016e5c4c0ExploitThird Party Advisory
- https://wpscan.com/vulnerability/b5035987-6227-4fc6-bc45-1e8016e5c4c0ExploitThird Party Advisory
FAQ
What is CVE-2021-25016?
CVE-2021-25016 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Refle...
How severe is CVE-2021-25016?
CVE-2021-25016 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25016?
Check the references section above for vendor advisories and patch information. Affected products include: Premio Chaty, Premio Chaty Pro.