WordPress Plugin Vulnerabilities

BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR

Description

The plugin does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

Proof of Concept

Affects Plugins

Fixed in 14.5.0

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Mustafa Ahmed
Submitter
Mustafa Ahmed
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other