One to one user Chat by WPGuppy

One to one user Chat by WPGuppy has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 5 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high. 2025 was the busiest year with 5 disclosures.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (17%). Other recurring categories include Deserialization Of Untrusted Data, Incorrect Privilege Assignment.

5 of the records (83%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

5 independent researchers contributed these findings, most of them (2) reported by I8BL. One to one user Chat by WPGuppy is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage83%
Open

1

Fixed

5

Get automatic notifications for all One to one user Chat by WPGuppy vulnerabilities before they are exploited.

Most severe open issueCVSS 5.3CVE-2025-6792

One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception

Read the full analysis

Vulnerability Records

6 records
One to one user Chat by WPGuppy banner
Latestv1.1.6

One to one user Chat by WPGuppy

AmentoTech Private Limited

Author

AmentoTech Private Limited

4.2(5)
84/100
Last Updated
2026-03-12 (6mo ago)
Active Installs
600+
Downloads
26,503
Requires WP
6.0+
Requires PHP
8.1+
Tested up to
WP 6.9.7
Created
2022-03-04 (5y ago)

WPGuppy is a well thought and clinically designed and developed WordPress chat plugin which has been engineered to fulfill the market needs. It is loaded with features without compromising on quality. WPGuppy is not just a simple WordPress chat plugin – it is a comprehensive chat solution entailing features that are hard to find in a single WordPress chat plugin. It is a comprehensive feature-rich WordPress chat plugin that not only provides numerous practical features for end-users but has been designed and developed keeping in mind the high-quality standards that subsequently provide the much-needed robustness and working performance in such plugins. This plugin prides itself on using its built-in database which means that it will be integrated within your WordPress site database and you get to keep complete control on how you manage your data etc. The team behind this plugin consists of experienced and professional software engineers and web designers who back this plugin with excellent customer support. Enable PHP HTTP Authorization Header Shared Hosts Most shared hosts have disabled the HTTP Authorization Header by default. To enable this option you’ll need to edit your .htaccess file by adding the following: RewriteEngine on RewriteCond %{HTTP:Authorization} ^(.*) RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1] WPEngine To enable this option you’ll need to edit your .htaccess file by adding the following: SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1 What’s new in WP Guppy Pro ** BudyPress & BudyBoss Integration ** ** Post base chat ** ** Start chat on the WooCommerce shop page ** Emoji sharing ** Voice note ** ** Group chat with friends ** Create group Delete group Upload group avatar Leave group Share video files Share documents Share gallery or single images Send audio files Hot: Send current location with open street maps Hot: Reply to a message Delete a message from a chat Download attachments Real-time chat with pusher.com Channel API, Vue.js, and Vuex Real-time chat with node.js and socket.io. Your server should support node.js for this to activate the real-time experience All WordPress users listed by roles Media and attachment listing in the chat sidebar User profile management Reset the database with a single click from the back-end Settings for the default tab to activate Enable/disable tabs for the user, chats, friends, blocked Dynamic color schemes Media extensions to upload settings Mute bell sound for notifications Report user via email All media attachments download from a conversation Clear conversation RTL support Much more features, click here to check all the features

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C