CVE · Medium

CVE-2022-40216 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 1.9.10.71

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-40216 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 1.9.10.71 Improper Access Control Medium 4.3 < 1.9.10.71 1.9.10.71 2022-11-09

CVE-2022-40216

The Better Messages plugin for WordPress contains an authorization bypass vulnerability in versions through 1.9.10.68 that allows attackers with subscriber-level access to circumvent messaging restrictions. The flaw stems from inadequate access control implementation within the plugin's messaging features. This vulnerability enables low-privileged users to override configured messaging blocks and controls. The issue is resolved in version 1.9.10.71 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.