SecAlerts
w

wordplus

Security Risk Profile

41
/100
medium

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from November 1, 2021 to present

11
Total CVEs
5
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
41/100
medium

Severity Distribution

Critical
0
High
5
Medium
6
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
CSRF
3
3
SSRF
2
4
Infoleak
1

Most Affected Products

1. WordPlus Better Messages Wordpress11
2. Better Messages Live Chat1
3. Better Messages Better Messages1
4. Better Messages Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss1

Recent Vulnerabilities

See more →
CVE-2024-13697
CVSS 6.5medium

Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links

Mar 1, 2025🔧 No Patch
CVE-2024-13611
CVSS 7.5high

Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

Mar 1, 2025🔧 No Patch
CVE-2024-13612
CVSS 6.4medium

Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Feb 1, 2025
CVE-2023-49168
CVSS 6.5medium

WordPress BP Better Messages Plugin <= 2.4.0 is vulnerable to Cross Site Scripting (XSS)

Dec 14, 2023
CVE-2022-41609
CVSS 8.8high

WordPress Better Messages plugin <= 1.9.10.68 - Server-Side Request Forgery (SSRF) vulnerability

Nov 18, 2022🔧 No Patch
CVE-2022-40216
CVSS 6.5medium

WordPress Better Messages plugin <= 1.9.10.69 - Auth. Messaging Block Bypass vulnerability

Nov 18, 2022🔧 No Patch
CVE-2022-36389
CVSS 8.8high

WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability

Aug 23, 2022
CVE-2022-33142
CVSS 7.7high

WordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerability

Aug 23, 2022
CVE-2022-29454
CVSS 4.3medium

WordPress Better Messages plugin <= 1.9.9.148 - Cross-Site Request Forgery (CSRF) vulnerability

Jul 20, 2022
CVE-2021-24809
CVSS 8.8high

BP Better Messages < 1.9.9.41 - Multiple CSRF

Nov 1, 2021

Monitor wordplus in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.