CVE Database /
CVE-2024-13697
CVE · Medium
CVE-2024-13697 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13697
|
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.5 |
Server-Side Request Forgery (SSRF) |
Medium
4.8
|
< 2.7.5
|
2.7.5 |
2025-02-28 |
—
|
CVE-2024-13697
The Better Messages plugin for WordPress contains a Server-Side Request Forgery vulnerability affecting versions 2.7.4 and earlier through the 'nice_links' parameter. Unauthenticated attackers can exploit this flaw to send web requests to arbitrary destinations from the affected server, potentially allowing them to access or modify data from internal services. This vulnerability is exploitable only when the "Enable link previews" feature is active, which is the default configuration. The issue was patched in version 2.7.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings