CVE Database /
CVE-2024-32802
CVE · Medium
CVE-2024-32802 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.4.33
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-32802
|
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.4.33 |
Missing Authorization |
Medium
5.3
|
< 2.4.33
|
2.4.33 |
2024-04-22 |
—
|
CVE-2024-32802
The Better Messages plugin for WordPress fails to properly verify user permissions when accessing chat rooms, allowing unauthenticated attackers to view chat rooms they should not be able to access. This authorization bypass vulnerability affects all versions up to and including 2.4.32, with the flaw stemming from insufficient permission checks on chatroom access. Attackers without proper credentials can exploit this weakness to gain unauthorized visibility into private or restricted chat functionality.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings