CVE-2025-6792
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to access and read private chat messages between users without needing to log in. It affects all versions of the One to One user Chat by WPGuppy plugin up to version 1.1.4, making it easy for anyone to intercept these messages if they know where to look.
Technical Description
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 14, 2026
about 2 months ago
Last Modified
Feb 18, 2026
about 2 months ago