High 7.5
2026-03-05< 3.5.2
CVE-2026-27370
Minimum safe version
3.5.2
Update to 3.5.2 or later to address 12 fixable vulnerabilities
CVE-2026-27370
WordPress Chaty Plugin <= 3.3.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4149
CVE-2024-2972
CVE-2023-47759
Chaty < 3.1 - Admin+ Stored Cross-Site Scripting
CVE-2023-3245
CVE-2023-25019
Chaty <= 3.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2022-3858
CVE-2021-36846
CVE-2021-25016