CVE Database /
CVE-2021-24809
CVE · High
CVE-2021-24809 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 1.9.9.170
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24809
|
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 1.9.9.170 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 1.9.9.170
|
1.9.9.170 |
2021-10-04 |
—
|
CVE-2021-24809
The BP Better Messages plugin version prior to 1.9.9.41 fails to implement cross-site request forgery protections on several AJAX functions, including those for leaving chats, joining chats, leaving threads, muting/unmuting threads, and adding or removing users from threads. An attacker could exploit this weakness to trick authenticated users into performing unintended actions on the plugin without their knowledge or consent.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings