← WordPress Vulnerabilities
WordPress security by component

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 7.7.

Plugin slug: bp-better-messages

CVE-2026-16585: Better Messages sticker deletion permits administrator-level arbitrary file deletion

Better Messages through 2.15.19 lets an Administrator store a sticker file URL containing ../ traversal through normalize_sticker(), which applies esc_url_raw() but does not remove traversal segments. A DELETE request to /wp-json/better-messages/v1/admin/sticker-packs/{id}/stickers/{sticker_id} reaches delete_sticker(); its uploads-URL prefix test passes before the relative path is URL-decoded and appended to the uploads directory, after which unlink() deletes the resolved target. This can remove arbitrary files readable by the hosting account and may lead to denial of service or code execution depending on the file removed.

PublishedJul 28, 2026
Known safe version> 2.15.19
Safe version
Jul 28, 2026 CVE-2026-16585
Better Messages sticker deletion permits administrator-level arbitrary file deletion
Better Messages through 2.15.19 lets an Administrator store a sticker file URL containing ../ traversal through normalize_sticker(), which applies esc_url_raw() but does not remove traversal segments. A DELETE request to /wp-json/better-messages/v1/admin/sticker-packs/{id}/stickers/{sticker_id} reaches delete_sticker(); its uploads-URL prefix test passes before the relative path is URL-decoded and appended to the uploads directory, after which unlink() deletes the resolved target. This can remove arbitrary files readable by the hosting account and may lead to denial of service or code execution depending on the file removed.
> 2.15.19
CVE7.2
NVDPending
May 27, 2026 CVE-2026-42736
BP Better Messages: A security weakness
BP Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.14.16.
2.15.0
CVE7.5
NVDPending
Mar 01, 2025 CVE-2024-13611
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Sensitive information exposure
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Feb 01, 2025 CVE-2024-13612
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Cross-site scripting
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2024-32802
BP Better Messages: A security weakness
BP Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 14, 2023 CVE-2023-49168
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Cross-site scripting
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 19, 2022 CVE-2022-41609
Bp Better Messages: Server-side request forgery
Bp Better Messages is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.4
NVD8.8
Nov 18, 2022 CVE-2022-40216
Bp Better Messages: A security weakness
Bp Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.5
Aug 23, 2022 CVE-2022-36389
Bp Better Messages: Cross-site request forgery
Bp Better Messages is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Aug 23, 2022 CVE-2022-33142
Bp Better Messages: A security weakness
Bp Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.7
NVD6.5
Jul 20, 2022 CVE-2022-29454
Bp Better Messages: Cross-site request forgery
Bp Better Messages is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE3.1
NVD4.3