Executive brief
BP Better Messages is a WordPress plugin that enables messaging functionality for BuddyPress communities. An unauthenticated attacker can inject malicious JavaScript code that executes in the browsers of site visitors, potentially stealing cookies, session tokens, or hijacking user accounts. Exploitation requires tricking a user into clicking a malicious link or visiting a specially crafted page.
Technical details
This is an unauthenticated stored or reflected cross-site scripting (XSS) vulnerability in BP Better Messages versions up to 2.15.27. The vulnerability arises from insufficient input validation or output encoding in user-supplied data. An attacker can craft a malicious payload and inject it through an unprotected endpoint; a victim user's browser then executes the injected script, allowing the attacker to steal session cookies, perform actions on behalf of the victim, or redirect them to phishing pages. User interaction is required for exploitation. The vulnerability is patched in version 2.15.28 and later.
Affected products
- Automattic BP Better Messages <=2.15.27
Timeline
- 2026-09-03: disclosed: Published on NVD
- 2026-09-02: patched: Version 2.15.28 released