Impact
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress contains a SQL injection flaw in its handling of the 'group_id' message meta parameter. The code fails to properly escape or bind this user‑supplied value, allowing attackers with subscriber‑level permissions or higher to append arbitrary SQL to an existing query. Successful exploitation would let a threat actor read sensitive information from the database, including user accounts, message contents, or any other data stored within the WordPress database. The vulnerability does not enable code execution, but it does provide a clear path to data disclosure.
Affected Systems
Any WordPress installation running any version of Better Messages up to and including 3.0.4 and that has the BuddyBoss Platform plugin installed with its Social Groups component disabled is affected. The disabling state persists after deactivation of the component, so previously‑disabled sites remain vulnerable until the plugin is updated or the component is re‑enabled and cleaned. Site owners using the plugin for chat rooms, group chat, private messages, or AI chat bots should verify the plugin version and the BuddyBoss component state.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is not available, but no listing in the CISA KEV catalog reduces the likelihood of widespread exploitation. The attack requires the victim to be logged in with subscriber or higher privileges and the vulnerable configuration of BuddyBoss. Once those prerequisites are met, an attacker can inject malicious SQL to read database tables, constituting an information‑disclosure risk. Because the flaw requires credentials, the threat horizon is limited to authenticated users, but the impact remains significant once exploited.
OpenCVE Enrichment