CVE-2026-89334: Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to access the full message transcript, thread metadata, and user data of any chat-room thread without authentication. This is only exploitable when the chat room's onlyjoinedcanread setting retains its default value of '0'.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Botsto a version that resolves this vulnerability.Fixed in 2.15.33 - Configuration
Set chat room setting only_joined_can_read to a value other than the default '0' (the issue is exploitable when only_joined_can_read retains default value '0').
Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots (WordPress plugin) only_joined_can_read = 0