CVE-2026-89093 PUBLISHED

Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register

Assigner: Wordfence
Reserved: 10.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the is_ai_bot_user() function identifying privileged internal AI bot accounts by performing a prefix check for 'ai-chat-bot-' against a guest record's stored IP address, which is populated verbatim from the client-controlled X-Real-IP request header during unauthenticated guest registration. This makes it possible for unauthenticated attackers to register a guest identity that the plugin treats as its own internal AI bot, bypassing the per-room role allowlist, draft-status check, and join filters — which are all short-circuited by the bot check in user_can_join() and user_can_read() — to join administrator-restricted chat rooms, post messages into them, and read the private message history of other users.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor wordplus
Product Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
Versions Default: unaffected
  • affected from 0 to 2.15.33 (incl.)

Credits

  • Jonah Burgess (CryptoCat) finder

References

Problem Types

  • CWE-287 Improper Authentication CWE