Bp Better Messages Wordplus Bp Better Messages

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wordplus Bp Better Messages.

By the Year

In 2026 there have been 3 vulnerabilities in Wordplus Bp Better Messages with an average score of 7.2 out of ten. Bp Better Messages did not have any published security vulnerabilities last year. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 3 7.23
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 7.45

It may take a day or so for new Bp Better Messages vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wordplus Bp Better Messages Security Vulnerabilities

Unauth XSS in BP Better Messages <=2.15.27
CVE-2026-84812 7.1 - High - September 03, 2026

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

XSS

Unauthenticated XSS in BP Better Messages 2.15.22
CVE-2026-32547 7.1 - High - August 18, 2026

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.

XSS

BP Better Messages<2.14.16 Auth Bypass via User-Controlled Key
CVE-2026-42736 7.5 - High - May 27, 2026

Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16.

Insecure Direct Object Reference / IDOR

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_
CVE-2021-24809 8.8 - High - November 01, 2021

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions

Session Riding

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute
CVE-2021-24808 6.1 - Medium - November 01, 2021

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wordplus Bp Better Messages or by Wordplus? Click the Watch button to subscribe.

Wordplus
Vendor

subscribe