HTML5 Chat
HTML5 Chat has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for HTML5 Chat has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. HTML5 Chat is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-12451HTML5 chat <= 1.07 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

HTML5 Chat
Author
proxymis
HTML5 Chat allows you to quickly add a live audio and video chat to any WordPress page or post. The plugin embeds the HTML5-based chat service from html5-chat.com, without requiring any technical configuration. Once activated, you can insert the chat anywhere using a simple shortcode. Key features: – Live audio & video chat (HTML5) – Simple shortcode integration – Customizable width & height – Fullscreen mode support – Admin moderation tools – CSS customization via admin panel – Works on desktop and mobile browsers After activation, your chat access credentials are automatically sent to your WordPress admin email. Security note: Version 1.07 includes a security fix for a stored Cross-Site Scripting (XSS) vulnerability in shortcode attributes (CVE-2024-12451). Credit: Peter Thaleikis / Wordfence. Support For questions or assistance, please contact: contact@proxymis.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C