WordPress · Chatra Live Chat + Chatbot + Cart Saver · CVE-2026-12041
**Name of the Vulnerable Software and Affected Versions**
Chatra Live Chat + ChatBot + Cart Saver versions prior to 1.0.13
**Description**
Insufficient input sanitization and output escaping in the admin settings allow authenticated attackers with administrator-level permissions and above to perform Stored Cross-Site Scripting (XSS). This occurs when arbitrary web scripts are injected via the `chatra-code` setting, which then execute when a user accesses the affected page. This issue specifically impacts multi-site installations and environments where `unfiltered html` has been disabled.
**Recommendations**
Update Chatra Live Chat + ChatBot + Cart Saver to a version newer than 1.0.12.
Restrict access to the `chatra-code` setting to minimize the risk of exploitation.