THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18404 (MEDIUM 6.4) — The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes

[NVD] CVE-2026-18404 (MEDIUM 6.4) — The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes

mednvdPublished 2026-09-05

CVE-2026-18404 CVSS: 6.4 MEDIUM Published: 2026-09-05T06:17:09.577

The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18404