Impact
This vulnerability is a reflected cross‑site scripting flaw in the Better Messages plugin for WordPress. An unauthenticated attacker can embed malicious JavaScript in the "icn" parameter, which is echoed back without proper sanitization. When a victim visits a crafted link or URLs containing the manipulated parameter, the script runs in the victim's browser, potentially stealing session cookies, defacing content, or redirecting the user to malicious sites. The impact is client‑side code execution under the victim's user context, affecting confidentiality and integrity of data in the victim's session.
Affected Systems
The flaw exists in the Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin (wordplus) for WordPress versions up to and including 2.15.22. Any WordPress installation running this plugin is susceptible unless it has been updated to a later release such as 2.15.23. The vulnerability is tied to the plugin's shortcode handling and is not limited to specific operating systems or server configurations.
Risk and Exploitability
The assignment gives the vulnerability a CVSS score of 6.1, indicating a moderate risk. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, so no current exploitation campaigns are confirmed. An attacker can exploit the flaw by crafting a malicious link containing a malicious "icn" value and luring a user to visit it; no special privileges are required. Therefore, the threat is primarily tied to social engineering and URL manipulation.
OpenCVE Enrichment