CVE-2026-0736 | Collect.chat Chatbot Plugin up to 2.4.8 on WordPress _inpost_head_script[synth_header_script] cross site scripting
A vulnerability, which was classified as problematic, was found in Collect.chat Chatbot Plugin up to 2.4.8 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument _inpost_head_script[synth_header_script] results in cross site scripting.
This vulnerability is cataloged as CVE-2026-0736. The attack may be launched remotely. There is no exploit available.