Skip to content
Noroxi

Simple Ajax Chat – Add a Fast, Secure Chat Box

simple-ajax-chat · plugin

Known security vulnerabilities for Simple Ajax Chat – Add a Fast, Secure Chat Box. Find out in seconds which version runs on your site with WP Lens.

7 known vulnerabilities

6 exploitable without logging in · 1 with public exploit code · latest Sep 11, 2026

Listed on wordpress.org · latest 20260827 · last updated Aug 27, 2026 · 2K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2022-27849unauthenticated≤ 20220115

    WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability

    High 7.5
  • CVE-2026-81825unauthenticated≤ 20260811

    Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting

    High 7.2
  • CVE-2026-2987unauthenticated · needs a click≤ 20260217

    Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c'

    Medium 6.1
  • CVE-2022-25610unauthenticated · needs a click≤ 20220115

    WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability

    Medium 6.1
  • CVE-2026-3075unauthenticated≤ 20251121

    WordPress Simple Ajax Chat plugin <= 20251121 - Sensitive Data Exposure vulnerability

    Medium 5.3
  • CVE-2024-2956admin≤ 20231101

    Simple Ajax Chat <= 20231101 - Authenticated (Admin+) Stored Cross-Site Scripting

    Medium 4.4
  • CVE-2022-27850unauthenticated · needs a click≤ 20220115

    WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory