The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 311 live websites that are affected by CVE-2026-13005.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 311 live websites (91% of MxChat install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 37 versions ( 97% of all versions) |
| 99 websites | |
| 25 websites | |
| 17 websites | |
| 14 websites | |
| 12 websites | |
| 11 websites | |
| 10 websites | |
| 10 websites | |
| 8 websites | |
| 8 websites |
| .com | 131 websites |
| .org | 16 websites |
| .de | 16 websites |
| .com.au | 11 websites |
| .it | 11 websites |
| .net | 8 websites |
| .fr | 5 websites |
| .ch | 5 websites |
| .dk | 5 websites |
| .ca | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************************.org | ***,*** | ||
| *********.com | ***,*** | ||
| *************.org | ***,*** | ||
| **.cu | ***,*** | ||
| *********.org | ***,*** | ||
| **********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| **********************.ro | ***,*** | ||
| ***********.dk | ***,*** | ||
| **********.es | *,***,*** |
FAQ