Vulnerabilities / Better Messages / WPSEC-2026-0731

Better Messages <= 3.0.13 - Unauthenticated Missing Authorization to User Listing via getUsers REST API Endpoint

Medium 5.3 CWE-862Fixed in 3.0.14
ID
WPSEC-2026-0731
Plugin
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots (bp-better-messages)
Affected
from 2.15.0 before 3.0.14
Remediation
Update to 3.0.14 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
Better Messages on WPSec AttackSurface
Fix released
Published

Description

The Better Messages plugin for WordPress is vulnerable to unauthorized access of data via the better-messages/v1/getUsers REST API endpoint in all versions up to, and including, 3.0.13, due to the route being registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to list and search the site's members and their profile data (user ID, display name, avatar, profile URL and last activity), even on sites that do not use the Users widget or restrict it to certain roles.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0