
CVE-2025-6792 The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/cha… https://www.cve.org/CVERecord?id=CVE-2025-6792
Post summary
The post discloses a missing capability check in WPGuppy’s chat endpoint that allows unauthorized data access.

