Wordplus Wordplus

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Wordplus product.

RSS Feeds for Wordplus security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Wordplus products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Wordplus Sorted by Most Security Vulnerabilities since 2018

Wordplus Better Messages13 vulnerabilities

Wordplus Bp Better Messages5 vulnerabilities

By the Year

In 2026 there have been 8 vulnerabilities in Wordplus with an average score of 6.6 out of ten. Last year, in 2025 Wordplus had 4 security vulnerabilities published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.41.




Year Vulnerabilities Average Score
2026 8 6.61
2025 4 6.20
2024 1 6.30
2023 1 5.40
2022 5 5.16
2021 2 7.45

It may take a day or so for new Wordplus vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wordplus Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-89093 Sep 19, 2026
WordPress Better Messages <=2.15.33 Info Exposure via Spoofing (Guest IP) The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check for `'ai-chat-bot-'` against a guest record's stored IP address, which is populated verbatim from the client-controlled `X-Real-IP` request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters which are all short-circuited by the bot check in `user_can_join()` and `user_can_read()` to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users.
Better Messages
CVE-2026-89334 Sep 19, 2026
Authorization Bypass in Better Messages Chat Rooms WP Plugin v2.15.33 The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.
Better Messages
CVE-2026-18555 Sep 16, 2026
Reflected XSS in Better Messages 2.15.22 (WordPress), via icn param The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'icn' parameter in all versions up to, and including, 2.15.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2026-84812 Sep 03, 2026
Unauth XSS in BP Better Messages <=2.15.27 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Bp Better Messages
CVE-2026-32547 Aug 18, 2026
Unauthenticated XSS in BP Better Messages 2.15.22 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
Bp Better Messages
CVE-2026-16585 Jul 28, 2026
WordPress Better Messages <=2.15.19 Arbitrary File Deletion via delete_sticker The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The prefix check intended to restrict deletion to the uploads directory can be bypassed by crafting a URL that begins with the legitimate uploads base URL but embeds ../ traversal sequences in the path portion, as the normalize_sticker function only applies esc_url_raw(), which does not strip ../ sequences, allowing the traversal payload to be stored verbatim in WordPress options.
CVE-2026-42736 May 27, 2026
BP Better Messages<2.14.16 Auth Bypass via User-Controlled Key Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16.
Bp Better Messages
CVE-2024-13362 May 01, 2026
WordPress Plugins XSS via URL (CVE-2024-13362) Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2025-14154 Dec 17, 2025
Stored XSS in Better Messages Live Chat WP plugin <=2.10.2 via guest display name The Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display name in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-13611 Mar 01, 2025
Info Exposure in Better Messages <=2.6.9 via /wp-content/uploads The Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/bp-better-messages directory which can contain file attachments included in chat messages.
Better Messages
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.