Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections. | |
| Title | BuddyPress 14.4.0 Friends List IDOR via REST API | |
| First Time appeared |
Buddypress
Buddypress buddypress |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:buddypress:buddypress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Buddypress
Buddypress buddypress |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T12:59:09.543Z
Reserved: 2026-06-09T23:14:36.037Z
Link: CVE-2026-53675
Updated: 2026-06-10T12:59:06.206Z
Status : Deferred
Published: 2026-06-10T00:16:55.323
Modified: 2026-06-10T19:41:25.327
Link: CVE-2026-53675
No data.
OpenCVE Enrichment
Updated: 2026-06-10T03:15:20Z