Sceawere

Vulnerability Detail

CVE-2026-87764UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BuddyPress Instant Chat Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
BuddyPress Instant Chat
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts that will execute in the session of any member who later views that conversation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T07:17:26.913Z",
  "pubdate": "2026-10-11T07:17:26.913Z",
  "executiveSummary": "The BuddyPress Instant Chat WordPress plugin, in all versions through 1.6, is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.\nThe vulnerability stems from a critical lack of input validation and authorization checks, allowing an unauthenticated attacker to inject malicious JavaScript payloads into chat conversations.\nThese scripts are subsequently executed within the browser sessions of authenticated users, such as administrators or other members, who view the compromised chat messages.\nThe impact is significant, potentially allowing for session hijacking, unauthorized administrative actions, sensitive data theft, or site defacement.\nThis vulnerability is particularly dangerous as it requires no prior authentication or administrative privileges to execute.\nThe flaw affects the entire chat message processing lifecycle, from message submission to rendering, creating a high-risk exposure for WordPress sites utilizing the plugin.",
  "technicalDetails": "The root cause of the vulnerability is twofold: a broken access control mechanism and a lack of output encoding within the message handling routines of BuddyPress Instant Chat.\nThe plugin fails to verify the identity of the message sender against the conversation participants, allowing an unauthenticated remote actor to submit chat messages to any session.\nFurthermore, the plugin does not implement proper sanitization or context-aware output encoding when rendering message content in the user interface.\nThe exploitation flow begins with an attacker identifying the endpoint used by the plugin to process chat messages. Because the plugin lacks authorization checks, the attacker can submit a POST request containing a malicious payload in the 'message' parameter.\nThis payload is stored directly in the underlying database without any filtering or neutralization of HTML or JavaScript tags.\nWhen a legitimate user, such as an administrator, accesses the chat interface, the plugin retrieves the malicious payload from the database and renders it into the document object model (DOM) of the victim's browser.\nBecause the payload is injected into the application's context, the browser executes the script under the victim's authenticated session.\nThe victim's browser treats the injected script as trusted content originating from the site itself, bypassing the Same-Origin Policy (SOP).\nPost-exploitation impact includes the ability to perform actions on behalf of the authenticated user, such as creating new administrator accounts, modifying site configurations, or scraping private user communications.\nThe attack is persistent and occurs whenever the affected chat history is accessed, ensuring maximum exposure once the malicious payload has been successfully stored in the database.\nThe vulnerability is present in versions through 1.6 and is fully exploitable over the network without requiring any prior interaction with the target application's administrative interface."
}
CVE-2026-87764: BuddyPress Instant Chat Stored XSS (HIGH Severity, CVSS: 8.8) | Sceawere