Impact
The Better Messages – Chat Rooms WordPress plugin contains an authorization bypass in its REST API endpoint that allows an authenticated user with custom or higher access to retrieve the full message transcript, thread metadata, and user data from any chat‑room thread. The flaw is caused by the plugin not verifying that the requesting user has permission to access the requested data, resulting in a data disclosure vulnerability.
Affected Systems
All releases of the Better Messages plugin from its initial version up to and including 2.15.33 are affected. Users who have installed or upgraded to 2.15.33 or earlier may be vulnerable unless they have applied a newer patch. The vulnerability has been observed in the WordPress environment where the plugin is deployed as a chat component.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so exfiltration risk remains uncertain until further data is published. Exploitation requires the attacker to be a logged‑in user with at least custom‑level access and the chat room’s only_joined_can_read setting must remain at its default value of 0. The attacker can then send a request to the REST endpoint '/thread/<id>' to retrieve sensitive conversation data, making this a potentially valuable threat for insiders or compromised accounts.
OpenCVE Enrichment