CVE-2021-24809: BP Better Messages < 1.9.9.41 - Multiple CSRF
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bpbettermessagesleavechat, bpbettermessagesjoinchat, bpmessagesleavethread, bpmessagesmutethread, bpmessagesunmutethread, bpbettermessagesaddusertothread, bpbettermessagesexcludeuserfromthread. This could allow attackers to make logged in users do unwanted actions
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24809?
CVE-2021-24809 has been classified as a medium severity vulnerability due to its potential impact on user security.
How do I fix CVE-2021-24809?
To fix CVE-2021-24809, update the BP Better Messages WordPress plugin to version 1.9.9.41 or later.
What type of vulnerability is CVE-2021-24809?
CVE-2021-24809 is a Cross-Site Request Forgery (CSRF) vulnerability affecting AJAX actions in the BP Better Messages plugin.
Which versions of BP Better Messages are affected by CVE-2021-24809?
Versions of BP Better Messages before 1.9.9.41 are affected by CVE-2021-24809.
What actions are vulnerable in CVE-2021-24809?
CVE-2021-24809 affects multiple AJAX actions including joining and leaving chats, muting, and unmuting threads.