Plugin Vulnerability Hub
Plugin 11 known issues Latest disclosed Feb 24, 2026

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Vulnerabilities

Review known vulnerability records for the WordPress plugin Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty (`chaty`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-27370, CVE-2025-1450 and CVE-2024-4149, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
11
High or Critical
1
Patch Coverage
100%
Last Updated
Mar 05, 2026
Priority CVE Quick Links

Fast paths into Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
CVE-2022-3858 High 3.0.3
CVE-2022-3858 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty SQL Injection

Floating Chat Widget - Chaty <= 3.0.2 - Authenticated (Administrator+) SQL Injection

CVE-2025-1450 Medium 3.3.6
CVE-2025-1450 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Stored Cross-Site Scripting

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

CVE-2023-25019 Medium 3.1
CVE-2023-25019 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Cross-Site Scripting

Chaty <= 3.0.9 - Reflected Cross-Site Scripting

CVE-2021-25016 Medium 2.8.3
CVE-2021-25016 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Cross-Site Scripting

Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button - Chaty <= 2.8.2 Reflected Cross-Site Scripting

CVE-2024-2972 Medium 3.1.9
CVE-2024-2972 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Stored Cross-Site Scripting

Floating Chat Widget <= 3.1.8 - Authenticated (Editor+) Stored Cross-Site Scripting

CVE-2026-27370 Medium 3.5.2
CVE-2026-27370 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Sensitive Information Exposure

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 - Unauthenticated Information Exposure

CVE-2021-36846 Medium 2.8.5
CVE-2021-36846 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Stored Cross-Site Scripting

Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.3 - Admin+ Stored Cross-Site Scripting

CVE-2024-4149 Medium 3.2.3
CVE-2024-4149 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Stored Cross-Site Scripting

Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
11 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2026-27370, CVE-2025-1450 and CVE-2024-4149
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2025-1450 Medium Patch path listed

CVE-2025-1450: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripti...

Published
Feb 26, 2025
Patch Status
3.3.6
CVE-2024-4149 Medium Patch path listed

CVE-2024-4149: Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripti...

Published
May 23, 2024
Patch Status
3.2.3
Known Vulnerabilities

Reports for Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-27370
CVE-2026-27370: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 - Unauthenticated Information Exposure

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1. This makes it possible for unauthenticated attack...

Published
Feb 24, 2026
Patched Release
3.5.2
Affected Versions
Versions up to 3.5.1
Next Step
Update to 3.5.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-1450
CVE-2025-1450: Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insuf...

Published
Feb 26, 2025
Patched Release
3.3.6
Affected Versions
Versions up to 3.3.5
Next Step
Update to 3.3.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4149
CVE-2024-4149: Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.2 due to insufficient inpu...

Published
May 23, 2024
Patched Release
3.2.3
Affected Versions
Versions up to 3.2.2
Next Step
Update to 3.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2972
CVE-2024-2972: Floating Chat Widget <= 3.1.8 - Authenticated (Editor+) Stored Cross-Site Scripting

The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cht_social_Whatsapp[bg_color] parameter in all versions up to, and including, 3...

Published
Apr 03, 2024
Patched Release
3.1.9
Affected Versions
Versions up to 3.1.8
Next Step
Update to 3.1.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-47759
CVE-2023-47759: Chaty <= 3.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.2 due to insufficient input sanitiza...

Published
Nov 13, 2023
Patched Release
3.1.3
Affected Versions
Versions up to 3.1.2
Next Step
Update to 3.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-3245
CVE-2023-3245: Floating Chat Widget - Chaty <= 3.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Floating Chat Widget - Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin...

Published
Jun 26, 2023
Patched Release
3.1.2
Affected Versions
Versions up to 3.1.1
Next Step
Update to 3.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-25019
CVE-2023-25019: Chaty <= 3.0.9 - Reflected Cross-Site Scripting

The Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'channel' parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...

Published
May 16, 2023
Patched Release
3.1
Affected Versions
Versions up to 3.0.9
Next Step
Update to 3.1 or newer if supported.
Plugin Medium Patched: Yes
Chaty <= 3.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting

The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Published
May 16, 2023
Patched Release
3.1
Affected Versions
Versions up to 3.0.9
Next Step
Update to 3.1 or newer if supported.
Plugin High Patched: Yes CVE-2022-3858
CVE-2022-3858: Floating Chat Widget - Chaty <= 3.0.2 - Authenticated (Administrator+) SQL Injection

The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the $chaty_leads parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...

Published
Nov 14, 2022
Patched Release
3.0.3
Affected Versions
Versions up to 3.0.2
Next Step
Update to 3.0.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-36846
CVE-2021-36846: Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.3 - Admin+ Stored Cross-Site Scripting

Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin)

Published
Apr 07, 2022
Patched Release
2.8.5
Affected Versions
Versions up to 2.8.3
Next Step
Update to 2.8.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25016
CVE-2021-25016: Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button - Chaty <= 2.8.2 Reflected Cross-Site Scripting

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

Published
Dec 06, 2021
Patched Release
2.8.3
Affected Versions
Versions before 2.8.3
Next Step
Update to 2.8.3 or newer if supported.