VYPR

BuddyPress Instant Chat

by WordPress

CVEs (1)

  • CVE-2026-87764Oct 11, 2026
    risk 0.00cvss —epss —

    The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts…