PT-2026-95742 · WordPress · Bp Better Messages

·

CVE-2026-89093

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots versions prior to 2.15.34
Description The plugin is subject to information exposure through spoofing. The is ai bot user() function identifies privileged internal AI bot accounts by checking for the 'ai-chat-bot-' prefix in a guest record's stored IP address. This IP address is taken directly from the client-controlled X-Real-IP request header during unauthenticated guest registration at the /guests/register endpoint. Consequently, unauthenticated attackers can register a guest identity that the system recognizes as an internal AI bot. This allows them to bypass the per-room role allowlist, draft-status checks, and join filters—which are bypassed by the bot check in user can join() and user can read() functions—enabling them to join administrator-restricted chat rooms, post messages, and read the private message history of other users.
Recommendations Update the plugin to a version newer than 2.15.33.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89093

Affected Products

Bp Better Messages