PT-2026-8061 · WordPress · Wpguppy

Published

2026-02-14

·

Updated

2026-02-14

·

CVE-2025-6792

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPGuppy plugin for WordPress versions up to and including 1.1.4
Description The One to one user Chat by WPGuppy plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize API endpoint. This allows unauthenticated attackers to intercept and view private chat messages between users.
Recommendations Update the WPGuppy plugin to a version later than 1.1.4.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-6792

Affected Products

Wpguppy