CVE Database /
CVE-2024-13611
CVE · High
CVE-2024-13611 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13611
|
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0 |
Exposure of Sensitive Information to an Unauthorized Actor |
High
7.5
|
< 2.7.0
|
2.7.0 |
2025-02-28 |
—
|
CVE-2024-13611
The Better Messages plugin for WordPress and its compatible social platforms is susceptible to unauthorized access of sensitive data in versions 2.6.9 and earlier. Unauthenticated users can retrieve confidential information from the /wp-content/uploads/bp-better-messages directory, which stores file attachments that users have shared within chat conversations. This vulnerability allows attackers without login credentials to download chat-related files that should remain private. The issue was addressed in version 2.7.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings