Executive brief
BP Better Messages is a WordPress plugin that enables messaging functionality for users on WordPress sites. A vulnerability in versions 2.15.22 and earlier allows unauthenticated attackers to inject malicious JavaScript code into pages, which can steal visitor data, hijack user accounts, or redirect users to malicious sites. The attack requires a privileged user to perform an action (such as clicking a malicious link), but the attacker themselves does not need authentication to exploit it.
Technical details
The plugin contains a reflected or stored cross-site scripting (XSS) vulnerability that allows injection of malicious scripts without authentication. While the attack vector is network-based and requires user interaction (a victim must click a malicious link or visit a crafted page), no authentication is required on the attacker's side. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the vulnerable website, leading to credential theft, session hijacking, or malware distribution. The vulnerability has been patched in version 2.15.23 and later.
Affected products
- BuddyBoss BP Better Messages <= 2.15.22
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Version 2.15.23 or later