One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception

2026-02-13 18:16
Jonas Benjamin Friedli

Strategic Overview

Status
Unpatched
Affected Version<= 1.1.4
CVSS5.3Medium
CVECVE-2025-6792
View all One to one user Chat by WPGuppy vulnerabilities

Vulnerability Overview

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-306 (Missing Authentication for Critical Function) The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C