Description
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check for `'ai-chat-bot-'` against a guest record's stored IP address, which is populated verbatim from the client-controlled `X-Real-IP` request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters — which are all short-circuited by the bot check in `user_can_join()` and `user_can_read()` — to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure & Unauthorized Access to Restricted Chats
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an authentication bypass delivered via spoofing of the X‑Real‑IP header during guest registration. An unauthenticated attacker can set the header to begin with the string ‘ai‑chat‑bot‑’, causing the plugin’s is_ai_bot_user() function to mistakenly recognize the guest as an internal AI bot. That triggers internal checks that skip the normal per‑room role allowlist, draft‑status verification, and join filters, allowing the attacker to join rooms reserved for administrators, post messages, and read private chat history. This produces a confidentiality and integrity violation for all users in the compromised rooms and is classified as CWE‑287.

Affected Systems

The affected product is the WordPress plugin Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots from vendor Wordplus. All releases up to and including version 2.15.33 contain the flaw; no other versions are mentioned as affected.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the moderate range. The EPSS metric is not reported, and the flaw is not listed in CISA KEV. The attack path is straightforward: any unauthenticated visitor can send a HTTP POST to /guests/register with a crafted X‑Real‑IP header that begins with ‘ai‑chat‑bot‑’. Because the plugin unquestioningly trusts that header, the probability of exploitation is high on sites that expose the guest registration endpoint. Successful exploitation lets an attacker gain authorization to access rooms reserved for administrators, post messages, and read private conversations, thereby compromising confidentiality and integrity of the chat data.

Generated by OpenCVE AI on September 19, 2026 at 10:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Better Messages to version 3.0.0 or later, eliminating the vulnerable prefix check.
  • If an upgrade is not feasible, block or strip the X‑Real‑IP header from unauthenticated requests to WordPress, or configure the web server to ignore that header for unauthenticated traffic.
  • Disable or restrict guest registration for the plugin, ensuring only authenticated users can register or that guest registration is turned off entirely.
  • Enforce stricter role checks in the chat configuration so that only authenticated administrators can join protected rooms, preventing the AI bot bypass.

Generated by OpenCVE AI on September 19, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordplus
Wordplus better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress
Wordpress wordpress
Vendors & Products Wordplus
Wordplus better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` function identifying privileged internal AI bot accounts by performing a prefix check for `'ai-chat-bot-'` against a guest record's stored IP address, which is populated verbatim from the client-controlled `X-Real-IP` request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters — which are all short-circuited by the bot check in `user_can_join()` and `user_can_read()` — to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users.
Title Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:26.022Z

Reserved: 2026-09-10T20:32:26.852Z

Link: CVE-2026-89093

cve-icon Vulnrichment

Updated: 2026-09-19T13:56:38.764Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:16.443

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-89093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses