PT-2026-47132 · WordPress · Click To Chat – Wa Widget

·

CVE-2026-7795

·

Published

2026-06-06

·

Updated

2026-06-07

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Click to Chat – WA Widget versions prior to 4.39
Description The plugin is subject to Stored Cross-Site Scripting. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages. This occurs because the CCW Shortcode::shortcode() function insufficiently escapes the num parameter within the [chat] shortcode. While esc attr() is applied, the resulting HTML entities are decoded by browsers when placed inside HTML event-handler attributes, such as the onclick attribute in style template files (e.g., 'sc-style-1.php'). This allows a payload to break out of the JavaScript window.open() string literal and execute arbitrary code when a user clicks the WhatsApp chat button.
Recommendations Update the plugin to a version later than 4.38. As a temporary workaround, avoid using the num parameter in the [chat] shortcode until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7795

Affected Products

Click To Chat – Wa Widget