CVE-2026-4653: Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter
The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4653?
The severity of CVE-2026-4653 is medium with a score of 6.4.
What type of vulnerability is CVE-2026-4653?
CVE-2026-4653 is a Stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2026-4653?
To fix CVE-2026-4653, update the Block, Suspend, Report for BuddyPress plugin to the latest version.
Who is affected by CVE-2026-4653?
Authenticated users with subscriber or higher roles are affected by CVE-2026-4653.
What causes CVE-2026-4653?
CVE-2026-4653 is caused by insufficient input sanitization and output escaping of the 'link' parameter.