Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages. | |
| Title | BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter | |
| First Time appeared |
Buddypress
Buddypress buddypress |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:buddypress:buddypress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Buddypress
Buddypress buddypress |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T18:10:40.143Z
Reserved: 2026-06-09T23:14:36.036Z
Link: CVE-2026-53673
Updated: 2026-06-10T18:10:36.044Z
Status : Deferred
Published: 2026-06-10T00:16:55.040
Modified: 2026-06-10T19:41:25.327
Link: CVE-2026-53673
No data.
OpenCVE Enrichment
Updated: 2026-06-10T04:30:05Z