CVE · High

CVE-2024-13611 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13611 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.7.0 2.7.0 2025-02-28

CVE-2024-13611

The Better Messages plugin for WordPress and its compatible social platforms is susceptible to unauthorized access of sensitive data in versions 2.6.9 and earlier. Unauthenticated users can retrieve confidential information from the /wp-content/uploads/bp-better-messages directory, which stores file attachments that users have shared within chat conversations. This vulnerability allows attackers without login credentials to download chat-related files that should remain private. The issue was addressed in version 2.7.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.