AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-25016

MEDIUM · CVSS 6.1 EPSS 1.80%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-25016
Severity
MEDIUM
CVSS
6.1
EPSS
1.80%
WordPress

Original NVD Description

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting