CVE-2026-2987 identifies a Stored Cross-Site Scripting (XSS) vulnerability within the Simple Ajax Chat plugin for WordPress, affecting versions up to 20260217. This flaw stems from insufficient input sanitization and output escaping of the 'c' parameter, enabling unauthenticated attackers to inject arbitrary web scripts. Rated 6.1 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N), it has a low attack complexity but requires user interaction for script execution. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Specialk | Simple Ajax Chat – Add A Fast, Secure Chat Box | >= 0, <= 20260217CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.