Description
The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts that will execute in the session of any member who later views that conversation.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The BuddyPress Instant Chat WordPress plugin through version 1.6 fails to verify that a chat message originates from a participant of the conversation it is being added to and it also fails to escape message content before rendering it. This allows unauthenticated users to store arbitrary JavaScript. When an authenticated member later views the conversation, the malicious script executes in the context of that member’s browser session, potentially enabling credential theft, session hijacking, or other malicious actions within that user’s account. The vulnerability is a classic stored cross‑site scripting flaw that directly impacts confidentiality, integrity, and availability of the affected site’s users.

Affected Systems

BuddyPress Instant Chat plugin for WordPress. All installations running version 1.6 or earlier are vulnerable. The issue is tied to the plugin’s chat module and does not affect other BuddyPress components or WordPress core.

Risk and Exploitability

The lack of an authorization check and output sanitization allows a threat actor to inject code via the chat interface, targeting any visitor who views the affected conversation. While the EPSS score is currently unavailable, the nature of stored XSS suggests that exploitation is feasible with moderate effort, and the absence of a KEV listing indicates that no known large‑scale exploits are publicly documented. The attack vector is the web interface accessible by unauthenticated users, and any legitimate user who opens the conversation after the injection can become a victim.

Generated by OpenCVE AI on October 11, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade BuddyPress Instant Chat to the latest release that contains the sender‑authentication and output‑escaping fix.
  • If upgrading is not immediately possible, disable the instant chat functionality for unauthenticated users or restrict chat message creation to authenticated members only.
  • Implement input sanitization on incoming chat messages (e.g., use WordPress’s esc_html or esc_js) and ensure all output is properly escaped before rendering.

Generated by OpenCVE AI on October 11, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts that will execute in the session of any member who later views that conversation.
Title BuddyPress Instant Chat <= 1.6 - Unauthenticated Stored XSS via Chat Message
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.245Z

Reserved: 2026-09-09T07:22:46.726Z

Link: CVE-2026-87764

cve-icon Vulnrichment

Updated: 2026-10-11T11:19:45.486Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.913

Modified: 2026-10-11T12:17:25.390

Link: CVE-2026-87764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')