Wordplus Better Messages
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Wordplus Better Messages.
By the Year
In 2026 there have been 2 vulnerabilities in Wordplus Better Messages with an average score of 5.9 out of ten. Last year, in 2025 Better Messages had 3 security vulnerabilities published. Right now, Better Messages is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 0.33
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 5.90 |
| 2025 | 3 | 6.23 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 5.40 |
| 2022 | 5 | 5.16 |
| 2021 | 2 | 7.45 |
It may take a day or so for new Better Messages vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wordplus Better Messages Security Vulnerabilities
WordPress Better Messages <=2.15.33 Info Exposure via Spoofing (Guest IP)
CVE-2026-89093
5.3 - Medium
- September 19, 2026
The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check for `'ai-chat-bot-'` against a guest record's stored IP address, which is populated verbatim from the client-controlled `X-Real-IP` request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters which are all short-circuited by the bot check in `user_can_join()` and `user_can_read()` to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users.
authentification
Authorization Bypass in Better Messages Chat Rooms WP Plugin v2.15.33
CVE-2026-89334
6.5 - Medium
- September 19, 2026
The Better Messages Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.
AuthZ
Better Messages 2.7.4 SSRF via nice_links – Unauth Web Request
CVE-2024-13697
4.8 - Medium
- March 01, 2025
The Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default).
SSRF
Info Exposure in Better Messages <=2.6.9 via /wp-content/uploads
CVE-2024-13611
7.5 - High
- March 01, 2025
The Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/bp-better-messages directory which can contain file attachments included in chat messages.
Information Disclosure
Better Messages Live Chat WP Plugin XSS (2.6.9) via Shortcode
CVE-2024-13612
6.4 - Medium
- February 01, 2025
The Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
XSS
Better Messages Live Chat XSS in v<=2.4.0
CVE-2023-49168
5.4 - Medium
- December 14, 2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss allows Stored XSS.This issue affects Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: from n/a through 2.4.0.
XSS
Better Messages 1.9.10.68 SSRF Vulnerability (Subscriber+ Auth)
CVE-2022-41609
6.4 - Medium
- November 19, 2022
Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.
SSRF
Auth Bypass in Better Messages <=1.9.10.69 (WordPress) CVE-2022-40216
CVE-2022-40216
4.3 - Medium
- November 18, 2022
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
Authorization
WordPress BetterMessages <=1.9.10.57 Authenticated DoS (subscriber)
CVE-2022-33142
7.7 - High
- August 23, 2022
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
Resource Exhaustion
WordPlus Better Messages <=1.9.9.148 WP Plugin CSRF Vulnerability
CVE-2022-36389
4.3 - Medium
- August 23, 2022
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.
Session Riding
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress
CVE-2022-29454
3.1 - Low
- July 20, 2022
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.
Session Riding
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_
CVE-2021-24809
8.8 - High
- November 01, 2021
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions
Session Riding
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute
CVE-2021-24808
6.1 - Medium
- November 01, 2021
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Wordplus Better Messages or by Wordplus? Click the Watch button to subscribe.