Impact
The vulnerability is an authentication bypass delivered via spoofing of the X‑Real‑IP header during guest registration. An unauthenticated attacker can set the header to begin with the string ‘ai‑chat‑bot‑’, causing the plugin’s is_ai_bot_user() function to mistakenly recognize the guest as an internal AI bot. That triggers internal checks that skip the normal per‑room role allowlist, draft‑status verification, and join filters, allowing the attacker to join rooms reserved for administrators, post messages, and read private chat history. This produces a confidentiality and integrity violation for all users in the compromised rooms and is classified as CWE‑287.
Affected Systems
The affected product is the WordPress plugin Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots from vendor Wordplus. All releases up to and including version 2.15.33 contain the flaw; no other versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate range. The EPSS metric is not reported, and the flaw is not listed in CISA KEV. The attack path is straightforward: any unauthenticated visitor can send a HTTP POST to /guests/register with a crafted X‑Real‑IP header that begins with ‘ai‑chat‑bot‑’. Because the plugin unquestioningly trusts that header, the probability of exploitation is high on sites that expose the guest registration endpoint. Successful exploitation lets an attacker gain authorization to access rooms reserved for administrators, post messages, and read private conversations, thereby compromising confidentiality and integrity of the chat data.
OpenCVE Enrichment