Skip to main content

Vendor archive

wordplus CVEs

Beta · best-effort

11 CVEs tagged to vendor wordplus0 Critical, 3 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2024-13697

Published Mar 1, 2025

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13611

Published Mar 1, 2025

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13612

Published Feb 1, 2025

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'b…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49168

Published Dec 14, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPlus Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultim…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-41609

Published Nov 19, 2022

Auth. (subscriber+) Server-Side Request Forgery (SSRF) vulnerability in Better Messages plugin 1.9.10.68 on WordPress.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33142

Published Aug 23, 2022

Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29454

Published Jul 20, 2022

Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-24809

Published Nov 1, 2021

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_me…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24808

Published Nov 1, 2021

The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1