Description
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Published: 2026-09-03
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross-site scripting weakness exists in the BP Better Messages WordPress plugin for versions 2.15.27 and earlier. The flaw allows an attacker to inject arbitrary JavaScript that is rendered in the web browser. This can result in session hijacking, credential theft, defacement, or the execution of further actions under the victim’s credentials, all without requiring authentication. The vulnerability is classified as CWE-79.

Affected Systems

The issue affects installations of the WordPress BP Better Messages plugin version 2.15.27 and any earlier releases. Any site that has the plugin installed and exposed to the public Internet is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. The exploitable target is any unauthenticated user who can visit a crafted URL or otherwise trigger the vulnerable output of the plugin. With an EPSS score not available, the concrete exploitation probability is uncertain, but the lack of an existing KEV listing does not negate the need to remediate promptly. The attacker’s path does not require privileged access or pre‑existing conditions beyond the plugin’s unauthenticated exposure.

Generated by OpenCVE AI on September 3, 2026 at 20:30 UTC.

Remediation

Vendor Solution

Update the WordPress BP Better Messages Plugin to the latest available version (at least 2.15.28).


OpenCVE Recommended Actions

  • Upgrade the BP Better Messages plugin to version 2.15.28 or later.
  • Remove or disable any front‑end components that expose the vulnerable endpoint if an upgrade is not immediately possible.
  • Implement server‑side input validation or content sanitization for user‑generated data that is handled by the plugin.

Generated by OpenCVE AI on September 3, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Title WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T16:31:57.216Z

Reserved: 2026-09-02T10:29:50.811Z

Link: CVE-2026-84812

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:29.033

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')