CVE-2024-1983

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plugin-planet:simple_ajax_chat:*:*:*:*:*:wordpress:*:*

History

05 May 2025, 18:38

Type Values Removed Values Added
First Time Plugin-planet simple Ajax Chat
Plugin-planet
CPE cpe:2.3:a:plugin-planet:simple_ajax_chat:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
References () https://wpscan.com/vulnerability/bf3a31de-a227-4db1-bd18-ce6a78dc96fb/ - () https://wpscan.com/vulnerability/bf3a31de-a227-4db1-bd18-ce6a78dc96fb/ - Exploit, Third Party Advisory

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/bf3a31de-a227-4db1-bd18-ce6a78dc96fb/ - () https://wpscan.com/vulnerability/bf3a31de-a227-4db1-bd18-ce6a78dc96fb/ -
Summary
  • (es) El complemento Simple Ajax Chat de WordPress anterior a 20240223 no impide que los visitantes utilicen nombres maliciosos al utilizar el chat, que se reflejarán sin sanitizar para otros usuarios.

01 Aug 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

20 Mar 2024, 13:00

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-20 05:15

Updated : 2025-05-05 18:38


NVD link : CVE-2024-1983

Mitre link : CVE-2024-1983

CVE.ORG link : CVE-2024-1983


JSON object : View

Products Affected

plugin-planet

  • simple_ajax_chat