CVE 5.3 MEDIUM

One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception_CVE-2025-6792

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.

Basic Information

ID CVE-2025-6792
Source Wordfence
Published Feb 14, 2026 at 06:42

Affected Product

Vendor amentotechpvtltd
Product One to one user Chat by WPGuppy
Version *
Affected Versions amentotechpvtltd One to one user Chat by WPGuppy *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.