Vulnerabilities > Premio > Floating Chat Widget > 3.2.3

DATE CVE VULNERABILITY TITLE RISK
2025-02-27 CVE-2025-1450 Cross-site Scripting vulnerability in Premio Floating Chat Widget
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping.
network
low complexity
premio CWE-79
5.4