Extension WordPress
Vulnérabilités Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
Cette page rassemble les failles publiées pour Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
17 fiches
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots <= 2.14.16 – Unauthenticated Insecure Direct Object Reference
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.14.16 due to missing validation on a…
*-2.14.16
2.15.0
27/05/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-2.6.7
2.7.0
30/04/2026
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 – Unauthenticated Stored Cross-Site Scripting
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display name in all versions up to, and including, 2.10.2 due to insufficient input…
*-2.10.2
2.10.3
16/12/2025
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible…
*-2.6.9
2.7.0
28/02/2025
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 – Unauthenticated Limited Server-Side Request Forgery in nice_links
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for…
*-2.7.4
2.7.5
28/02/2025
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient…
*-2.6.9
2.7.0
31/01/2025
BP Better Messages <= 2.4.32 – Missing Authorization
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.4.32. This is due to the plugin not properly verifying…
*-2.4.32
2.4.33
22/04/2024
BP Better Messages <= 2.4.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input…
*-2.4.0
2.4.1
29/11/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
1.9.10.72-2.1.17
2.1.18
18/07/2023
Better Messages <= 1.9.10.68 – Authorization Bypass to Blocking Control Bypass
The Better Messages plugin for WordPress is vulnerable to Authorization Bypass resulting in a block bypass on messaging controls in versions up to, and including, 1.9.10.68. This is due to insufficient or broken controls in the plugin. This…
*-1.9.10.68
1.9.10.69
09/11/2022
Better Messages <= 1.9.10.68 – Server-Side Request Forgery
The Better Messages plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to 1.9.10.68. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to interact with internal network hosts via specially crafted…
*-1.9.10.68
1.9.10.69
21/10/2022
Better Messages <= 1.9.10.57 – Resource Exhaustion
The Better Messages plugin for WordPress is vulnerable to Resource Exhaustion in versions up to, and including, 1.9.10.57 due to not limiting the size of individual messages. This allows attackers, with subscriber-level access or higher, to exhaust resources…
*-1.9.10.57
1.9.10.58
22/08/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 1.9.9.170)
1.9.9.170
04/03/2022
Better Messages <= 1.9.9.148 – Cross-Site Request Forgery
The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 19.9.148. This is due to missing nonce validation on the favorite() function. This makes it possible for unauthenticated attackers to…
*-1.9.9.148
1.9.9.149
18/01/2022
Better Messages <= 1.9.9.148 – Cross-Site Request Forgery
The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.9.148. This is due to missing or incorrect nonce validation on the bp_messages_favorite action. This makes it possible for unauthenticated…
*-1.9.9.148
1.9.9.149
18/01/2022
BP Better Messages <= 1.9.9.37 – Cross-Site Request Forgery
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actions
[*, 1.9.9.41)
1.9.9.41
04/10/2021
BP Better Messages <= 1.9.9.37 – Reflected Cross-Site Scripting
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
[*, 1.9.9.41)
1.9.9.41
04/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.