CVE-2024-1983
HIGHDescription
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
Is your site exposed to CVE-2024-1983?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| plugin-planet | simple_ajax_chat |
References
Frequently Asked Questions
What is CVE-2024-1983? +
How severe is CVE-2024-1983? +
What products are affected by CVE-2024-1983? +
How do I check if I'm vulnerable to CVE-2024-1983? +
Related Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This …
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored …
The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions …
The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow …
The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow …