CVE Database /
CVE-2024-13612
CVE · Medium
CVE-2024-13612 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13612
|
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 2.7.0
|
2.7.0 |
2025-01-31 |
—
|
CVE-2024-13612
The Better Messages plugin for WordPress versions up to 2.6.9 contains a stored cross-site scripting vulnerability in the 'better_messages_live_chat_button' shortcode. Authenticated users with contributor-level permissions or higher can inject malicious scripts through insufficiently sanitized shortcode attributes, allowing the injected code to execute for anyone viewing the affected page.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings