The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default).
Metrics
Affected Vendors & Products
References
History
Mon, 26 May 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordplus
Wordplus better Messages |
|
| CPEs | cpe:2.3:a:wordplus:better_messages:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wordplus
Wordplus better Messages |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Mar 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default). | |
| Title | Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-01T08:23:21.239Z
Updated: 2025-03-03T20:56:21.813Z
Reserved: 2025-01-23T23:19:17.165Z
Link: CVE-2024-13697
Updated: 2025-03-03T20:53:24.992Z
Status : Analyzed
Published: 2025-03-01T09:15:09.370
Modified: 2025-05-26T01:24:15.283
Link: CVE-2024-13697
No data.
ReportizFlow