rootpwn

medium · CVSS v3 6.5 · EPSS 0.00399

CVE-2026-89334

An authorization bypass vulnerability exists in the Better Messages WordPress plugin up to version 2.15.33 due to improper privilege verific

Overview

An authorization bypass vulnerability exists in the Better Messages WordPress plugin up to version 2.15.33 due to improper privilege verification. The flaw allows authenticated users with custom-level access or higher to read unauthorized chat transcripts, thread metadata, and user data. This occurs when specific default chat room settings remain unconfigured.

Description

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's only_joined_can_read setting retains its default value of '0'.

Impact

Authenticated attackers can view sensitive private communications and user data across chat rooms without proper membership or authorization, leading to a breach of confidentiality. Organizations utilizing the affected plugin versions and default settings are at risk of data exposure. The integrity and availability of the system remain unaffected by this specific flaw.

Remediation

Update the Better Messages plugin to version 2.15.34 or higher immediately. Review and modify chat room configuration settings, specifically ensuring that the 'only_joined_can_read' setting is properly enforced rather than retaining its default value of '0'. Audit user roles and custom access levels to ensure principle of least privilege.

Risk context

The vulnerability carries a CVSS v3 score of 6.5, categorized as medium severity. The current EPSS score is 0.00399, indicating a low immediate exploitation probability in the wild, but defenders should still patch proactively given the exposure of private messages.

Affected products

  • Better Messages plugin for WordPress

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
EPSS
0.00399

WordPress Plugin Authorization Bypass Privilege Escalation Information Disclosure Chat Defensive

← All CVEs