Impact
An unauthenticated cross-site scripting weakness exists in the BP Better Messages WordPress plugin for versions 2.15.27 and earlier. The flaw allows an attacker to inject arbitrary JavaScript that is rendered in the web browser. This can result in session hijacking, credential theft, defacement, or the execution of further actions under the victim’s credentials, all without requiring authentication. The vulnerability is classified as CWE-79.
Affected Systems
The issue affects installations of the WordPress BP Better Messages plugin version 2.15.27 and any earlier releases. Any site that has the plugin installed and exposed to the public Internet is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. The exploitable target is any unauthenticated user who can visit a crafted URL or otherwise trigger the vulnerable output of the plugin. With an EPSS score not available, the concrete exploitation probability is uncertain, but the lack of an existing KEV listing does not negate the need to remediate promptly. The attacker’s path does not require privileged access or pre‑existing conditions beyond the plugin’s unauthenticated exposure.
OpenCVE Enrichment