Impact
The BuddyPress Instant Chat WordPress plugin through version 1.6 fails to verify that a chat message originates from a participant of the conversation it is being added to and it also fails to escape message content before rendering it. This allows unauthenticated users to store arbitrary JavaScript. When an authenticated member later views the conversation, the malicious script executes in the context of that member’s browser session, potentially enabling credential theft, session hijacking, or other malicious actions within that user’s account. The vulnerability is a classic stored cross‑site scripting flaw that directly impacts confidentiality, integrity, and availability of the affected site’s users.
Affected Systems
BuddyPress Instant Chat plugin for WordPress. All installations running version 1.6 or earlier are vulnerable. The issue is tied to the plugin’s chat module and does not affect other BuddyPress components or WordPress core.
Risk and Exploitability
The lack of an authorization check and output sanitization allows a threat actor to inject code via the chat interface, targeting any visitor who views the affected conversation. While the EPSS score is currently unavailable, the nature of stored XSS suggests that exploitation is feasible with moderate effort, and the absence of a KEV listing indicates that no known large‑scale exploits are publicly documented. The attack vector is the web interface accessible by unauthenticated users, and any legitimate user who opens the conversation after the injection can become a victim.
OpenCVE Enrichment