Vulnerabilities / Better Messages / WPSEC-2026-0731
Better Messages <= 3.0.13 - Unauthenticated Missing Authorization to User Listing via getUsers REST API Endpoint
Medium 5.3
CWE-862Fixed in 3.0.14
- ID
- WPSEC-2026-0731
- Plugin
- Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots (bp-better-messages)
- Affected
- from 2.15.0 before 3.0.14
- Remediation
- Update to 3.0.14 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- Better Messages on WPSec AttackSurface
- Fix released
- Published
Description
The Better Messages plugin for WordPress is vulnerable to unauthorized access of data via the better-messages/v1/getUsers REST API endpoint in all versions up to, and including, 3.0.13, due to the route being registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to list and search the site's members and their profile data (user ID, display name, avatar, profile URL and last activity), even on sites that do not use the Users widget or restrict it to certain roles.
References
- https://wpsec.com/vuln/WPSEC-2026-0731/
- https://plugins.svn.wordpress.org/bp-better-messages/tags/3.0.14/
- https://wordpress.org/plugins/bp-better-messages/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS