CVE 5.3 MEDIUM

BuddyPress 14.4.0 Friends List IDOR via REST API_CVE-2026-53675

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

Basic Information

ID CVE-2026-53675
Source VulnCheck
Published Jun 9, 2026 at 23:44

Affected Product

Vendor BuddyPress
Product BuddyPress
Affected Versions BuddyPress BuddyPress 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.