# Better Messages <= 3.0.13 - Unauthenticated Missing Authorization to User Listing via getUsers REST API Endpoint

- **ID:** WPSEC-2026-0731
- **Plugin:** Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots (`bp-better-messages`), https://wordpress.org/plugins/bp-better-messages/
- **Affected versions:** from 2.15.0 before 3.0.14
- **Fixed in:** 3.0.14 (Update to 3.0.14 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bp-better-messages
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0731/

## Description

The Better Messages plugin for WordPress is vulnerable to unauthorized access of data via the better-messages/v1/getUsers REST API endpoint in all versions up to, and including, 3.0.13, due to the route being registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to list and search the site's members and their profile data (user ID, display name, avatar, profile URL and last activity), even on sites that do not use the Users widget or restrict it to certain roles.

## References

- https://wpsec.com/vuln/WPSEC-2026-0731/
- https://plugins.svn.wordpress.org/bp-better-messages/tags/3.0.14/
- https://wordpress.org/plugins/bp-better-messages/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0731/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
