A AegiFlow
HIGHCVSS 8.6EPSS 0.4%

CVE-2026-53673

CVE-2026-53673 updated by NVD

Published
2026-06-10
Modified
2026-08-12
EPSS percentile
30%
Sources
github-advisory, nvd

Summary

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistbuddypress/buddypress14.5.0

Remediation: Upgrade to 14.5.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.