CVE-2024-13362
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
Minimum safe version
2.10.3
Update to 2.10.3 or later to address 19 fixable vulnerabilities
CVE-2025-14154
CVE-2024-13697
CVE-2024-13611
WordPress BP Better Messages Plugin <= 2.6.9 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-32802
CVE-2023-49168
WordPress BP Better Messages Plugin < 2.1.21 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2022-40216
CVE-2022-41609
WordPress BP Better Messages Plugin <= 1.9.9.148 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2022-33142
WordPress BP Better Messages Plugin <= 1.9.9.148 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress BP Better Messages plugin < 1.9.9.170 - Sensitive Information Disclosure vulnerability
WordPress BP Better Messages plugin < 1.9.9.170 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24809
CVE-2021-24808