Impact
The Better Messages WordPress plugin contains a stored DOM‑based XSS flaw caused by inadequate input sanitization and decoding of HTML‑entity‑encoded strings in user display names. An authenticated user with subscriber permissions or higher can inject arbitrary JavaScript into a display name, which is later rendered in pages that display the name. When another user views such a page, the injected code executes in that user’s browser, allowing credential theft, session hijacking, or other client‑side attacks.
Affected Systems
This issue affects the "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots" plugin supplied by wordplus. All releases up to and including version 3.0.4 are vulnerable; version 3.0.5 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score is not available, suggesting no current evidence of exploitation. The flaw is not listed in the KEV catalogue. The attack requires only subscriber‑level access to modify a user’s display name; once stored, the payload executes in any user’s browser that views that name, representing a high‑impact client‑side vulnerability.
OpenCVE Enrichment