CVE · Medium

CVE-2024-32802 — Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.4.33

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-32802 Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.4.33 Missing Authorization Medium 5.3 < 2.4.33 2.4.33 2024-04-22

CVE-2024-32802

The Better Messages plugin for WordPress fails to properly verify user permissions when accessing chat rooms, allowing unauthenticated attackers to view chat rooms they should not be able to access. This authorization bypass vulnerability affects all versions up to and including 2.4.32, with the flaw stemming from insufficient permission checks on chatroom access. Attackers without proper credentials can exploit this weakness to gain unauthorized visibility into private or restricted chat functionality.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.