High 7.2
2025-06-17< 3.3.5
Wise Chat <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
Minimum safe version
3.3.5
Update to 3.3.5 or later to address 7 fixable vulnerabilities
Wise Chat <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header
CVE-2024-13613
Wise Chat < 2.8.4 - CSV Injection
CVE-2023-32504
Wise Chat <= 2.8.3 - CSV Injection
WordPress Wise Chat plugin <= 2.8.3 - CSV Injection vulnerability
WordPress Wise Chat plugin <= 2.6.3 - Reverse Tabnabbing vulnerability