Description
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Published: 2026-09-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

An unauthenticated cross-site scripting weakness exists in the BP Better Messages WordPress plugin for versions 2.15.27 and earlier. The flaw allows an attacker to inject arbitrary JavaScript that is rendered in the web browser. This can result in session hijacking, credential theft, defacement, or the execution of further actions under the victim’s credentials, all without requiring authentication. The vulnerability is classified as CWE-79.

Affected Systems

The issue affects installations of the WordPress BP Better Messages plugin version 2.15.27 and any earlier releases. Any site that has the plugin installed and exposed to the public Internet is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. The exploitable target is any unauthenticated user who can visit a crafted URL or otherwise trigger the vulnerable output of the plugin. With an EPSS score not available, the concrete exploitation probability is uncertain, but the lack of an existing KEV listing does not negate the need to remediate promptly. The attacker’s path does not require privileged access or pre‑existing conditions beyond the plugin’s unauthenticated exposure.

Generated by OpenCVE AI on September 3, 2026 at 20:30 UTC.

Remediation

Vendor Solution

Update the WordPress BP Better Messages Plugin to the latest available version (at least 2.15.28).


OpenCVE Recommended Actions

  • Upgrade the BP Better Messages plugin to version 2.15.28 or later.
  • Remove or disable any front‑end components that expose the vulnerable endpoint if an upgrade is not immediately possible.
  • Implement server‑side input validation or content sanitization for user‑generated data that is handled by the plugin.

Generated by OpenCVE AI on September 3, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordplus
Wordplus better Messages
Wordpress
Wordpress wordpress
Vendors & Products Wordplus
Wordplus better Messages
Wordpress
Wordpress wordpress

Sat, 05 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Title WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordplus Better Messages
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-05T01:52:44.805Z

Reserved: 2026-09-02T10:29:50.811Z

Link: CVE-2026-84812

cve-icon Vulnrichment

Updated: 2026-09-05T01:52:40.518Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:29.033

Modified: 2026-09-05T02:17:18.430

Link: CVE-2026-84812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:28:30Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')