Reflected Cross-Site Scripting Vulnerability in Better Messages Plugin by WordPress
CVE-2026-18555
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-18555?
The Better Messages plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate input validation and output encoding, particularly through the 'icn' parameter. This vulnerability allows unauthenticated attackers to relay malicious scripts in a user's browser session, which could lead to exposure of sensitive information or unauthorized actions if users are lured into clicking infected links.
Affected Version(s)
Better Messages β Chat Rooms, Group Chat, Private Messages & AI Chat Bots 0 <= 2.15.22