Impact
The vulnerability is an Insecure Direct Object Reference (IDOR) that allows an attacker to bypass authorization controls by supplying a user‑controlled key. An attacker can request messages belonging to other users, leading to disclosure of private conversations and the potential exposure of sensitive personal data. This is a CWE‑639 flaw where improper validation of user permissions enables unauthorized data access.
Affected Systems
WordPress sites that have installed the BP Better Messages plugin from the wordplus vendor, with all releases up to and including version 2.14.16 being vulnerable. Site owners must update or mitigate the plugin to protect user messages.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as High severity, reflecting the ease of exploitation and the impact on confidentiality. The EPSS score is not available, so the current likelihood of real‑world exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. Attackers would likely exploit this via standard web requests to the plugin’s endpoints, providing a remote web attack vector that can be triggered without additional privileges.
OpenCVE Enrichment