PT-2026-95742 · WordPress · Bp Better Messages
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots versions prior to 2.15.34
Description
The plugin is subject to information exposure through spoofing. The
is ai bot user() function identifies privileged internal AI bot accounts by checking for the 'ai-chat-bot-' prefix in a guest record's stored IP address. This IP address is taken directly from the client-controlled X-Real-IP request header during unauthenticated guest registration at the /guests/register endpoint. Consequently, unauthenticated attackers can register a guest identity that the system recognizes as an internal AI bot. This allows them to bypass the per-room role allowlist, draft-status checks, and join filters—which are bypassed by the bot check in user can join() and user can read() functions—enabling them to join administrator-restricted chat rooms, post messages, and read the private message history of other users.Recommendations
Update the plugin to a version newer than 2.15.33.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bp Better Messages