Description
Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Chat Support for Messenger: from n/a through <= 1.2.18.
Published: 2025-11-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Better Chat Support for Messenger plugin allows an attacker to access or manipulate functionality that should be restricted to privileged users, potentially exposing sensitive data or enabling further malicious activity. The flaw arises from incorrectly configured access control security levels in versions up to 1.2.18, as noted in the vendor description. The vulnerability gives an attacker the ability to perform actions that normally require higher permissions, thereby compromising the confidentiality, integrity, or availability of the underlying WordPress site data.

Affected Systems

The issue affects WordPress sites that have installed ThemeAtelier Better Chat Support for Messenger plugin version 1.2.18 or earlier. Only these versions are impacted; newer releases are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending crafted requests to the plugin’s admin or AJAX endpoints without proper authorization checks. An attacker may not need elevated privileges to exploit the flaw, making it potentially accessible to unauthenticated users who can identify vulnerable endpoints. Mitigating this risk requires applying official patch updates or implementing workaround controls as outlined below.

Generated by OpenCVE AI on April 29, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to the latest version that includes proper access control checks
  • If updating is not immediately possible, restrict access to the plugin’s administrative URLs by IP whitelisting or user capability restrictions
  • Disable or uninstall the plugin on sites where it is not required
  • Monitor HTTP logs for unusual requests targeting the plugin’s administrative or AJAX endpoints

Generated by OpenCVE AI on April 29, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 24 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Chat Support for Messenger: from n/a through <= 1.2.18.
Title WordPress Better Chat Support for Messenger plugin <= 1.2.18 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.093Z

Reserved: 2025-11-21T11:21:26.612Z

Link: CVE-2025-66113

cve-icon Vulnrichment

Updated: 2025-11-24T17:54:22.956Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:53.153

Modified: 2026-04-27T18:16:36.490

Link: CVE-2025-66113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:00:18Z

Weaknesses