CVE · Medium

CVE-2024-13697 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13697 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.5 Server-Side Request Forgery (SSRF) Medium 4.8 < 2.7.5 2.7.5 2025-02-28

CVE-2024-13697

The Better Messages plugin for WordPress contains a Server-Side Request Forgery vulnerability affecting versions 2.7.4 and earlier through the 'nice_links' parameter. Unauthenticated attackers can exploit this flaw to send web requests to arbitrary destinations from the affected server, potentially allowing them to access or modify data from internal services. This vulnerability is exploitable only when the "Enable link previews" feature is active, which is the default configuration. The issue was patched in version 2.7.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.