CVE-2024-13697

MEDIUM CVSS 3.1: 6.5 EPSS 0.28%
Updated May 26, 2025
Wordplus
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions before 2.7.5
Fixed In 2.7.5
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Wordplus
Public PoC No

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.4 via the 'nice_links'. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. Successful exploitation requires the "Enable link previews" to be enabled (default).

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Wordplus Better_Messages
cpe:2.3:a:wordplus:better_messages:*:*:*:*:*:wordpress:*:*
— 2.7.5