PT-2026-48337 · WordPress · Buddypress

CVE-2026-53675

·

Published

2026-06-09

·

Updated

2026-06-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BuddyPress version 14.4.0
Description An insecure direct object reference occurs in the friends REST API, allowing any authenticated attacker to enumerate the complete friend list of another user. This is possible because the get items permissions check() function only verifies that the requester is logged in and fails to check the ownership of the requested list. By querying the friends endpoint with an arbitrary user id, an attacker can disclose private social connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53675
GHSA-WMJR-58RF-XGRC

Affected Products

Buddypress