CVE-2024-13611
EUVD-2025-589001.03.2025, 09:15
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.9 via the 'bp-better-messages' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/bp-better-messages directory which can contain file attachments included in chat messages.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wordplus | better_messages | 𝑥 < 2.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration