CVE-2022-40216: WordPress Better Messages plugin <= 1.9.10.69 - Auth. Messaging Block Bypass vulnerability
Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Better Messages pluginto a version that resolves this vulnerability.Fixed in 1.9.10.71
Event History
Frequently Asked Questions
What is CVE-2022-40216?
CVE-2022-40216 is an Authentication (subscriber+) Messaging Block Bypass vulnerability in the Better Messages plugin <= 1.9.10.69 on WordPress.
What software is affected by CVE-2022-40216?
The Better Messages plugin version <= 1.9.10.69 on WordPress is affected by CVE-2022-40216.
How severe is CVE-2022-40216?
CVE-2022-40216 has a severity rating of medium with a CVSS score of 6.5.
How can I fix CVE-2022-40216?
To fix CVE-2022-40216, update the Better Messages plugin to version 1.9.10.71 or later.
Where can I find more information about CVE-2022-40216?
You can find more information about CVE-2022-40216 on the Patchstack website and the official WordPress plugin page for Better Messages.