ZeroHour

CVE-2026-84812

moderate

Unauthenticated Cross-Site Scripting (XSS) in BP Better Messages WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84812 is a cross-site scripting flaw (CWE-79) in the BP Better Messages WordPress plugin, affecting all versions up to and including 2.15.27. An unauthenticated attacker can inject malicious script content that is rendered in the messaging interface; per the CVSS vector, exploiting it requires a victim to view or interact with the crafted content (UI:R), and the flaw crosses the site boundary (S:C). A successful attack could let the attacker run script in a targeted user's browser, enabling actions such as session theft or unauthorized actions on behalf of the victim, with the CVSS scoring low confidentiality, integrity, and availability impact. Sites affected are those running the BP Better Messages plugin, typically BuddyPress/BuddyBoss-powered community sites with private messaging, on versions 2.15.27 or older. There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.1% (4th percentile).

What to do: Update BP Better Messages to the latest available release (any version newer than 2.15.27). Because exploitation requires user interaction and there are no known exploits or public PoCs, patching at your next maintenance cycle is reasonable, but avoid delaying indefinitely if your site hosts active multi-user messaging. After updating, there is no specific indicator data published, so standard hardening (reviewing recently created admin accounts and unusual site activity) is sufficient.

Affected
WordPlus BP Better Messages (WordPress plugin)<= 2.15.27
Estimated exposure
moderate≈10,000–20,000+ sites (plugin listed around 10,000+ active installs on WordPress.org) — BP Better Messages is listed with roughly 10,000+ active installations on WordPress.org and only applies to sites using its BuddyPress/BuddyBoss messaging features, so the plausible exposed population is a five-figure number of community…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.