{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpresssimple_ajax_chat_add_a_fast_secure_chat_box/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:simple_ajax_chat_add_a_fast_secure_chat_box:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-81825"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simple Ajax Chat – Add a Fast, Secure Chat Box (\u003c= 20260811)"],"_cs_severities":["high"],"_cs_tags":["xss","web-security","wordpress","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Simple Ajax Chat - Add a Fast, Secure Chat Box plugin for WordPress (versions up to and including 20260811) contains a critical security flaw involving stored cross-site scripting (XSS). The vulnerability stems from insufficient sanitization of user-provided chat messages and inadequate output escaping. Furthermore, the nonce mechanism intended to secure message submissions is publicly visible on the plugin's chat interface. This exposure renders the nonce-based authentication ineffective, enabling unauthenticated attackers to craft and submit malicious chat messages. Because these messages are stored persistently, the injected scripts are executed in the browsers of any site visitors who load a page containing the chat box. This vulnerability poses a significant risk to site administrators and users, as it allows for the theft of session tokens, unauthorized actions on behalf of the user, or redirection to malicious domains.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the WordPress site. This can lead to the compromise of administrator sessions, redirection of legitimate traffic, and the potential for site-wide defacement or further exploitation of site users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'Simple Ajax Chat' plugin to a version released after 20260811 immediately to remediate CVE-2026-81825.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous HTTP POST requests to the plugin's message submission endpoint containing script tags or encoded JavaScript strings.\u003c/li\u003e\n\u003cli\u003eAudit existing chat history for entries containing HTML tags, specifically \u0026lt;script\u0026gt;, \u0026lt;img\u0026gt;, or \u0026lt;iframe\u0026gt; elements, which may indicate existing exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T05:12:24Z","date_published":"2026-09-11T05:12:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-simple-ajax-chat-xss/","summary":"The Simple Ajax Chat plugin for WordPress contains a stored cross-site scripting vulnerability in versions \u003c= 20260811, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces and insufficient input sanitization.","title":"Stored XSS in Simple Ajax Chat WordPress Plugin via CVE-2026-81825","url":"https://feed.craftedsignal.io/briefs/2026-09-simple-ajax-chat-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:simple_ajax_chat_add_a_fast_secure_chat_box:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}