Impact
The BP Better Messages plugin for WordPress is vulnerable to unauthenticated cross‑site scripting for all releases up to and including 2.15.22. The flaw allows an attacker to inject arbitrary client‑side script that will execute in the web browsers of visitors who view pages or messages processed by the plugin. Such code injection can alter the appearance of a page, display malicious content, or interact with the client session as part of the normal user experience.
Affected Systems
All installations of the WordPress BP Better Messages plugin with version 2.15.22 or earlier are affected. The vulnerability is present in every WordPress site that has the plugin enabled, regardless of other configuration or user roles, until the plugin is upgraded to version 2.15.23 or later.
Risk and Exploitability
The stated CVSS score of 7.1 indicates a medium‑to‑high severity level. EPSS information is not available and the vulnerability is not listed in CISA KEV. Because the weakness is unauthenticated, any visitor can trigger the flaw by visiting a page where the plugin renders content; this is inferred from the description that the XSS is unauthenticated. Consequently the risk is significant for sites relying on BP Better Messages for user interaction.
OpenCVE Enrichment