Executive brief
Better Messages is a WordPress plugin providing chat rooms, group messaging, and AI chatbot features. An unauthenticated attacker can inject malicious scripts into pages through a crafted link, allowing them to steal user credentials, sessions, or perform actions on behalf of affected users if those users click the link.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the Better Messages WordPress plugin affecting versions up to 2.15.22. The vulnerability exists in the 'icn' parameter due to insufficient input sanitization and output escaping. An unauthenticated attacker can craft a malicious URL containing JavaScript code in the 'icn' parameter; when a user clicks the link, the injected script executes in their browser with their session privileges. The plugin fails to properly validate or escape user-supplied input before rendering it in the page output. A patch is available in version 2.15.23 or later.
Affected products
- Better Messages Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots up to and including 2.15.22
Timeline
- 2026-09-16: disclosed