Simple Ajax Chat – Add a Fast, Secure Chat Box
simple-ajax-chat · plugin
Known security vulnerabilities for Simple Ajax Chat – Add a Fast, Secure Chat Box. Find out in seconds which version runs on your site with WP Lens.
7 known vulnerabilities
6 exploitable without logging in · 1 with public exploit code · latest Sep 11, 2026
Listed on wordpress.org · latest 20260827 · last updated Aug 27, 2026 · 2K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- High 7.5
CVE-2022-27849unauthenticated≤ 20220115
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
- High 7.2
CVE-2026-81825unauthenticated≤ 20260811
Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting
- Medium 6.1
CVE-2026-2987unauthenticated · needs a click≤ 20260217
Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c'
- Medium 6.1
CVE-2022-25610unauthenticated · needs a click≤ 20220115
WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
- Medium 5.3
CVE-2026-3075unauthenticated≤ 20251121
WordPress Simple Ajax Chat plugin <= 20251121 - Sensitive Data Exposure vulnerability
- Medium 4.4
CVE-2024-2956admin≤ 20231101
Simple Ajax Chat <= 20231101 - Authenticated (Admin+) Stored Cross-Site Scripting
- Medium 4.3
CVE-2022-27850unauthenticated · needs a click≤ 20220115
WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).