Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 7.7.
bp-better-messagesCVE-2026-16585: Better Messages sticker deletion permits administrator-level arbitrary file deletion
Better Messages through 2.15.19 lets an Administrator store a sticker file URL containing ../ traversal through normalize_sticker(), which applies esc_url_raw() but does not remove traversal segments. A DELETE request to /wp-json/better-messages/v1/admin/sticker-packs/{id}/stickers/{sticker_id} reaches delete_sticker(); its uploads-URL prefix test passes before the relative path is URL-decoded and appended to the uploads directory, after which unlink() deletes the resolved target. This can remove arbitrary files readable by the hosting account and may lead to denial of service or code execution depending on the file removed.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-16585
Better Messages sticker deletion permits administrator-level arbitrary file deletion
Better Messages through 2.15.19 lets an Administrator store a sticker file URL containing ../ traversal through normalize_sticker(), which applies esc_url_raw() but does not remove traversal segments. A DELETE request to /wp-json/better-messages/v1/admin/sticker-packs/{id}/stickers/{sticker_id} reaches delete_sticker(); its uploads-URL prefix test passes before the relative path is URL-decoded and appended to the uploads directory, after which unlink() deletes the resolved target. This can remove arbitrary files readable by the hosting account and may lead to denial of service or code execution depending on the file removed.
|
> 2.15.19 |
CVE7.2
NVDPending
|
| May 27, 2026 |
CVE-2026-42736
BP Better Messages: A security weakness
BP Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.14.16.
|
2.15.0 |
CVE7.5
NVDPending
|
| Mar 01, 2025 |
CVE-2024-13611
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Sensitive information exposure
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Feb 01, 2025 |
CVE-2024-13612
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Cross-site scripting
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 17, 2024 |
CVE-2024-32802
BP Better Messages: A security weakness
BP Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 14, 2023 |
CVE-2023-49168
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss: Cross-site scripting
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 19, 2022 |
CVE-2022-41609
Bp Better Messages: Server-side request forgery
Bp Better Messages is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE6.4
NVD8.8
|
| Nov 18, 2022 |
CVE-2022-40216
Bp Better Messages: A security weakness
Bp Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD6.5
|
| Aug 23, 2022 |
CVE-2022-36389
Bp Better Messages: Cross-site request forgery
Bp Better Messages is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Aug 23, 2022 |
CVE-2022-33142
Bp Better Messages: A security weakness
Bp Better Messages is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.7
NVD6.5
|
| Jul 20, 2022 |
CVE-2022-29454
Bp Better Messages: Cross-site request forgery
Bp Better Messages is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE3.1
NVD4.3
|