Executive brief
BP Better Messages is a WordPress plugin used to provide private messaging and chat functionality for community websites. A security flaw allows unauthorized individuals to bypass access controls and potentially view sensitive private messages or user data by manipulating identifiers in web requests. This could lead to a significant breach of user privacy and exposure of confidential communications.
Technical details
The BP Better Messages plugin for WordPress (versions up to 2.14.16) contains an Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639. The flaw stems from an authorization bypass through a user-controlled key, where the application fails to properly validate if the requesting user has permission to access a specific object or resource. An unauthenticated remote attacker can exploit this by manipulating input parameters (such as message or user IDs) to access sensitive data they are not authorized to view. The vulnerability is resolved in version 2.15.0.
Affected products
- wordplus BP Better Messages (bp-better-messages) <= 2.14.16
Timeline
- 2026-04-27: other: Reported by researcher dodoh4t
- 2026-05-27: disclosed: Vulnerability disclosed by Patchstack
- 2026-05-27: patched: Fixed in version 2.15.0