CVE-2026-53673 – BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter

CVE ID :CVE-2026-53673

Published : June 10, 2026, 12:16 a.m. | 20 minutes ago

Description :BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user’s identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user’s private messages.

Severity: 8.6 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه