One to one user Chat by WPGuppy
One to one user Chat by WPGuppy has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 5 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2025 was the busiest year with 5 disclosures.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (17%). Other recurring categories include Deserialization Of Untrusted Data, Incorrect Privilege Assignment.
5 of the records (83%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
5 independent researchers contributed these findings, most of them (2) reported by I8BL. One to one user Chat by WPGuppy is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-6792One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception
Read the full analysisVulnerability Records

One to one user Chat by WPGuppy
Author
AmentoTech Private Limited
WPGuppy is a well thought and clinically designed and developed WordPress chat plugin which has been engineered to fulfill the market needs. It is loaded with features without compromising on quality. WPGuppy is not just a simple WordPress chat plugin – it is a comprehensive chat solution entailing features that are hard to find in a single WordPress chat plugin. It is a comprehensive feature-rich WordPress chat plugin that not only provides numerous practical features for end-users but has been designed and developed keeping in mind the high-quality standards that subsequently provide the much-needed robustness and working performance in such plugins. This plugin prides itself on using its built-in database which means that it will be integrated within your WordPress site database and you get to keep complete control on how you manage your data etc. The team behind this plugin consists of experienced and professional software engineers and web designers who back this plugin with excellent customer support. Enable PHP HTTP Authorization Header Shared Hosts Most shared hosts have disabled the HTTP Authorization Header by default. To enable this option you’ll need to edit your .htaccess file by adding the following: RewriteEngine on RewriteCond %{HTTP:Authorization} ^(.*) RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1] WPEngine To enable this option you’ll need to edit your .htaccess file by adding the following: SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1 What’s new in WP Guppy Pro ** BudyPress & BudyBoss Integration ** ** Post base chat ** ** Start chat on the WooCommerce shop page ** Emoji sharing ** Voice note ** ** Group chat with friends ** Create group Delete group Upload group avatar Leave group Share video files Share documents Share gallery or single images Send audio files Hot: Send current location with open street maps Hot: Reply to a message Delete a message from a chat Download attachments Real-time chat with pusher.com Channel API, Vue.js, and Vuex Real-time chat with node.js and socket.io. Your server should support node.js for this to activate the real-time experience All WordPress users listed by roles Media and attachment listing in the chat sidebar User profile management Reset the database with a single click from the back-end Settings for the default tab to activate Enable/disable tabs for the user, chats, friends, blocked Dynamic color schemes Media extensions to upload settings Mute bell sound for notifications Report user via email All media attachments download from a conversation Clear conversation RTL support Much more features, click here to check all the features
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C