CVE-2025-43839: WordPress BP Messages Tool plugin <= 2.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through 2.2.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool bp-messages-tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through <= 2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43839?
CVE-2025-43839 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting.
How does CVE-2025-43839 affect the BP Messages Tool?
CVE-2025-43839 allows attackers to exploit improper input handling leading to reflected XSS in BP Messages Tool versions up to 2.2.
How do I fix CVE-2025-43839?
To address CVE-2025-43839, upgrade the BP Messages Tool to the latest version that resolves this vulnerability.
What are the potential impacts of CVE-2025-43839?
Exploiting CVE-2025-43839 could allow attackers to execute malicious scripts in the user’s browser, potentially compromising user data.
Is CVE-2025-43839 present in versions after 2.2 of the BP Messages Tool?
CVE-2025-43839 specifically affects BP Messages Tool versions from n/a through 2.2, and later versions may have fixed this vulnerability.