What the vulnerability does
01Description
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.
Explanation of Vulnerability in Simple Terms
The Better Messages WordPress plugin version 1.9.10.57 and earlier contains a denial-of-service vulnerability. An authenticated user with low privileges can trigger a condition that makes the site unresponsive or crash. The vulnerability affects the entire site due to scope change, meaning other users and functionality may be impacted when exploited.
What an attacker can do
Make the site unresponsive or crash, affecting all users.
Potential impact on your site
Site downtime or performance degradation affecting all visitors until the plugin is updated or disabled.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
External resources