Remote Code Execution Vulnerability in BuddyPress Instant Chat Plugin by WordPress
CVE-2026-87764
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 October 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-87764?
The BuddyPress Instant Chat plugin for WordPress, up to version 1.6, allows unauthorized users to inject arbitrary web scripts into chat conversations. This oversight arises from insufficient checks that verify the sender's affiliation with the conversation. Additionally, there's a lack of output escaping for message content, leading to potential exploitation by attackers who can store scripts that execute in the sessions of other users who later access the conversation.
Affected Version(s)
BuddyPress Instant Chat 0 <= 1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.