PT-2026-66355 · Buddypress+1 · Buddypress

·

CVE-2026-1360

·

Published

2026-07-29

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BuddyPress versions prior to 14.5.1
Description Authenticated attackers with subscriber-level access and above can inject arbitrary PHP objects via XProfile textbox fields. This occurs because the bp unserialize profile field() function uses @unserialize() without the allowed classes parameter on user-controlled XProfile field data. This flaw may lead to remote code execution if a suitable POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is available in the WordPress environment.
Recommendations Update BuddyPress to version 14.5.1 or later.

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1360

Affected Products

Buddypress