The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default).
Metrics
Affected Vendors & Products
References
History
Mon, 26 May 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordplus
Wordplus better Messages |
|
CPEs | cpe:2.3:a:wordplus:better_messages:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wordplus
Wordplus better Messages |
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 01 Mar 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default). | |
Title | Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links | |
Weaknesses | CWE-918 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-03T20:56:21.813Z
Reserved: 2025-01-23T23:19:17.165Z
Link: CVE-2024-13697

Updated: 2025-03-03T20:53:24.992Z

Status : Analyzed
Published: 2025-03-01T09:15:09.370
Modified: 2025-05-26T01:24:15.283
Link: CVE-2024-13697

No data.