THREAT OPS › Threat News › [NVD] CVE-2026-18404 (MEDIUM 6.4) — The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes
[NVD] CVE-2026-18404 (MEDIUM 6.4) — The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes
CVE-2026-18404 CVSS: 6.4 MEDIUM Published: 2026-09-05T06:17:09.577
The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contr
Indicators of compromise
- CVE-2026-18404cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18404