CVE-2022-33142 HIGH

CVE-2022-33142: WordPress Better Messages plugin <= 1.9.10.57 - Denial Of Service (DoS) vulnerability

Vendor Wordplus
Product Better Messages (WordPress plugin)
Published August 23, 2022
Last update April 28, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Better Messages WordPress plugin version 1.9.10.57 and earlier contains a denial-of-service vulnerability. An authenticated user with low privileges can trigger a condition that makes the site unresponsive or crash. The vulnerability affects the entire site due to scope change, meaning other users and functionality may be impacted when exploited.

What an attacker can do

03Attacker Capabilities

Make the site unresponsive or crash, affecting all users.

Potential impact on your site

04Site Impact

Site downtime or performance degradation affecting all visitors until the plugin is updated or disabled.

Conditions required to exploit

05Prerequisites

Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).

Key dates

06Disclosure timeline

August 23, 2022 CVE published
April 28, 2026 Record updated