A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-53675

CVE-2026-53675 updated by NVD

Published
2026-06-10
Modified
2026-08-12
EPSS percentile
14%
Sources
github-advisory, nvd

Summary

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistbuddypress/buddypress

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.