# Wise Chat <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via Chat Message Links

- **ID:** WPSEC-2026-0482
- **Plugin:** Wise Chat (`wise-chat`), https://wordpress.org/plugins/wise-chat/
- **Affected versions:** all versions before 3.4.2
- **Fixed in:** 3.4.2 (Update to 3.4.2 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wise-chat
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0482/

## Description

The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link shortcodes in chat messages in all versions up to, and including, 3.4.1. The check meant to limit chat links to http, https, ftp and mailto addresses was not anchored to the start of the URL, so links using other schemes, such as javascript:, were rendered unchanged. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into chat messages that execute when a user clicks the link. Anonymous chat users can post messages by default.

## References

- https://wpsec.com/vuln/WPSEC-2026-0482/
- https://plugins.svn.wordpress.org/wise-chat/tags/3.4.2/
- https://wordpress.org/plugins/wise-chat/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0482/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
