CVE-2026-84812: WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BP Better Messages pluginto a version that resolves this vulnerability.Fixed in 2.15.28
Event History
Frequently Asked Questions
Which installations are affected?
BP Better Messages versions 2.15.27 and earlier are affected. The provided information does not identify any configuration prerequisite.
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need to log in before attempting exploitation.
Does an attacker need to convince someone to take an action?
Yes. The attack vector includes user interaction, indicating exploitation requires a user to interact with attacker-controlled content.
What is the potential impact if exploitation succeeds?
The supplied severity vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. This is an XSS vulnerability, so successful exploitation can involve execution of attacker-supplied script in a user's browser context.