Authorization Bypass Vulnerability in BP Better Messages Plugin by WordPress
CVE-2026-42736
7.5HIGH
What is CVE-2026-42736?
A vulnerability exists in the BP Better Messages plugin for WordPress, where attackers can exploit incorrectly configured access control security levels. This authorization bypass could allow unauthorized users to access sensitive features or data, undermining the integrity of user permissions. The issue affects versions of BP Better Messages up to and including 2.14.16. Site administrators are strongly advised to implement updates to mitigate potential risks.
Affected Version(s)
BP Better Messages 0 <= 2.14.16