Description
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.
Published: 2026-09-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass allowing disclosure of chat-room transcripts
Action: Immediate Patch
AI Analysis

Impact

The Better Messages – Chat Rooms WordPress plugin contains an authorization bypass in its REST API endpoint that allows an authenticated user with custom or higher access to retrieve the full message transcript, thread metadata, and user data from any chat‑room thread. The flaw is caused by the plugin not verifying that the requesting user has permission to access the requested data, resulting in a data disclosure vulnerability.

Affected Systems

All releases of the Better Messages plugin from its initial version up to and including 2.15.33 are affected. Users who have installed or upgraded to 2.15.33 or earlier may be vulnerable unless they have applied a newer patch. The vulnerability has been observed in the WordPress environment where the plugin is deployed as a chat component.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so exfiltration risk remains uncertain until further data is published. Exploitation requires the attacker to be a logged‑in user with at least custom‑level access and the chat room’s only_joined_can_read setting must remain at its default value of 0. The attacker can then send a request to the REST endpoint '/thread/<id>' to retrieve sensitive conversation data, making this a potentially valuable threat for insiders or compromised accounts.

Generated by OpenCVE AI on September 19, 2026 at 10:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Better Messages plugin to version 3.0.0 or later
  • Set the only_joined_can_read configuration value to a non‑default (e.g., 1) to prevent unauthorized read access
  • Restrict REST API endpoint access to appropriate roles or implement additional role‑based checks

Generated by OpenCVE AI on September 19, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordplus
Wordplus better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress
Wordpress wordpress
Vendors & Products Wordplus
Wordplus better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.
Title Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordplus Better Messages – Chat Rooms, Group Chat, Private Messages & Ai Chat Bots
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:26.491Z

Reserved: 2026-09-11T15:59:00.768Z

Link: CVE-2026-89334

cve-icon Vulnrichment

Updated: 2026-09-19T13:57:16.355Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:16.893

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-89334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses