The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.
References
Configurations
No configuration.
History
14 Feb 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-14 07:16
Updated : 2026-02-18 17:52
NVD link : CVE-2025-6792
Mitre link : CVE-2025-6792
CVE.ORG link : CVE-2025-6792
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
