VYPR

Wpguppy Lite

by WordPress

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-49910Hig0.538.20.00Oct 22, 2025Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4.
CVE-2025-6792Med0.345.30.00Feb 14, 2026The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.