What is CVE-2026-32547?
CVE-2026-32547 is an unauthenticated Cross Site Scripting (XSS) vulnerability in the BP Better Messages plugin versions 2.15.22 and earlier. It allows remote attackers to execute malicious scripts without any authentication. Users should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-32547, BP Better Messages plagininin 2.15.22 və daha əvvəlki versiyalarında aşkarlanmış autentifikasiya olunmamış Cross Site Scripting (XSS) zəifliyidir. Bu, uzaqdan hücumçulara heç bir giriş tələb etmədən zərərli skriptlərin icrasına imkan verə bilər. İstifadəçilər dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin does the CVE-2026-32547 vulnerability affect?
This vulnerability affects the BP Better Messages plugin.
Do attackers need authentication to exploit CVE-2026-32547?
No, this is an unauthenticated XSS vulnerability, meaning attackers can exploit it without any login required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.