WordPress security by component
WP Guppy
Plugin description
WP Guppy adds real-time private messaging and chat functionality to WordPress websites.
WP Guppy (wp-guppy) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 09, 2025; the highest published CVSS base score is 8.5.
Plugin slug:
wp-guppyLatest vulnerability
CVE-2025-31920: WP Guppy: SQL injection
WP Guppy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
| Safe version |
|
||
|---|---|---|---|
| Jun 09, 2025 |
CVE-2025-31920
WP Guppy: SQL injection
WP Guppy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Dec 27, 2021 |
CVE-2021-24997
WP Guppy: Sensitive information exposure
WP Guppy is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVEPending
NVD6.5
|