CVE-2026-32547: WordPress BP Better Messages plugin <= 2.15.22 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
Affected Software
1 affected component
wordpress/BP Better Messages<=2.15.22
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/plugin/bp-better-messagesto a version that resolves this vulnerability.Fixed in 2.15.23
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be considered exposed?
Sites using BP Better Messages version 2.15.22 or earlier are affected, according to the available information.
2
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable without authentication and has low attack complexity, but it requires user interaction. An attacker would need to cause a user to interact with the malicious content.
3
Is a non-default configuration required, and what can be done before patching?
The provided data does not identify a configuration prerequisite or any workaround. Treat affected installations as exposed until they can be updated to a version not listed as affected.