CVE-2026-53673 – BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter
CVE ID :CVE-2026-53673
Published : June 10, 2026, 12:16 a.m. | 20 minutes ago
Description :BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user’s identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user’s private messages.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…