Executive brief
The Better Messages WordPress plugin, which enables chat functionality including group chat and private messaging, fails to verify user permissions when accessing chat room data. Authenticated attackers can bypass authorization controls to view message transcripts, thread metadata, and user data from any chat room when default settings are in place, potentially exposing sensitive conversations and personal information.
Technical details
The plugin lacks proper authorization checks before granting access to chat room data, allowing authenticated users with custom-level access and above to read message transcripts and metadata regardless of the chat room's join status. The vulnerability requires the chat room's only_joined_can_read setting to remain at its default value of 0. An attacker with authenticated access can enumerate and retrieve sensitive chat data through direct API or function calls.
Affected products
- BuddyBoss Better Messages up to and including 2.15.33
Timeline
- 2026-09-19: disclosed