Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. buddypress/buddypress
  4. ›
  5. CVE-2026-53675

CVE-2026-53675: BuddyPress: Any authenticated attacker can enumerate another user's complete friend list via IDOR

June 10, 2026 (updated August 12, 2026)

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user’s complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users’ private social connections.

References

  • buddypress.org/
  • github.com/advisories/GHSA-wmjr-58rf-xgrc
  • nvd.nist.gov/vuln/detail/CVE-2026-53675
  • wordpress.org/plugins/buddypress
  • www.vulncheck.com/advisories/buddypress-friends-list-idor-via-rest-api

Code Behaviors & Features

Detect and mitigate CVE-2026-53675 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 14.4.0

Solution

Unfortunately, there is no solution available yet.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

packagist/buddypress/buddypress/CVE-2026-53675.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 12 Sep 2026 00:18:20 +0000.