HTML5 Chat

HTML5 Chat has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for HTML5 Chat has a vendor fix available, so running the current release closes it.

All of these findings were reported by Peter Thaleikis. HTML5 Chat is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all HTML5 Chat vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-12451

HTML5 chat <= 1.07 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
HTML5 Chat banner
Latestv1.08

HTML5 Chat

proxymis

Author

proxymis

3.3(9)
66/100
Last Updated
2026-01-20 (8mo ago)
Active Installs
100+
Downloads
13,753
Requires WP
4.5+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2017-11-04 (9y ago)

HTML5 Chat allows you to quickly add a live audio and video chat to any WordPress page or post. The plugin embeds the HTML5-based chat service from html5-chat.com, without requiring any technical configuration. Once activated, you can insert the chat anywhere using a simple shortcode. Key features: – Live audio & video chat (HTML5) – Simple shortcode integration – Customizable width & height – Fullscreen mode support – Admin moderation tools – CSS customization via admin panel – Works on desktop and mobile browsers After activation, your chat access credentials are automatically sent to your WordPress admin email. Security note: Version 1.07 includes a security fix for a stored Cross-Site Scripting (XSS) vulnerability in shortcode attributes (CVE-2024-12451). Credit: Peter Thaleikis / Wordfence. Support For questions or assistance, please contact: contact@proxymis.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C