CVE-2026-8155 PUBLISHED

BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR

Assigner: WPScan
Reserved: 08.05.2026 Published: 31.07.2026 Updated: 31.07.2026

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

Product Status

Vendor Unknown
Product BuddyPress
Versions Default: unaffected
  • affected from 0 to 14.5.0 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE