CVE-2026-8155

NONE EPSS 0.13%
Updated Jul 31, 2026
Unknown
Parameter Value
Affected Versions before 14.5.0
Type CWE-639 Authorization Bypass Through User-Controlled Key
Vendor Unknown
Public PoC No

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

Vulnerable Products

unknown:buddypress