CVE-2026-53673: BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter

Published Jun 9, 2026
·
Updated

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a userid parameter in the request. Attackers can pass another user's identifier to the getitempermissionscheck method, which validates the supplied userid instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.

Affected Software

1 affected component
BuddyPress BuddyPress=14.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove buddypress/messages from your environment.

    Uninstall or deactivate the BuddyPress Messages component if private messaging is not required to eliminate exposure of the vulnerable REST endpoints.

  2. Configuration

    Disable or restrict access to the BuddyPress messages REST API endpoints (the messages component REST endpoints that accept a user_id parameter) until an official patch is available. If disabling entirely is not possible, restrict access to trusted administrators only.

    BuddyPress Messages REST API REST endpoint access = disabled or restricted
  3. Compensating control

    Restrict network access to the WordPress REST API (wp-json) or the messages endpoints via firewall, WAF, or reverse-proxy rules so only trusted IPs or authenticated admin tooling can call these endpoints until a vendor fix is applied.

Event History

Jun 9, 2026
CVE Published
via MITRE·11:44 PM
Data Sourced
via MITRE·11:44 PM
DescriptionSeverityWeakness
Jun 10, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-53673?

The severity of CVE-2026-53673 is rated high with a CVSS score of 8.6.

2

How does CVE-2026-53673 affect BuddyPress users?

CVE-2026-53673 allows authenticated attackers to access arbitrary private message threads by exploiting an insecure direct object reference in the messages REST API.

3

Who is vulnerable to CVE-2026-53673?

User accounts in BuddyPress 14.4.0 that have been authenticated are vulnerable to CVE-2026-53673.

4

How do I fix CVE-2026-53673?

To resolve CVE-2026-53673, update BuddyPress to the latest version as recommended by the developers.

5

Is it possible for attackers to misuse CVE-2026-53673?

Yes, attackers can misuse CVE-2026-53673 to gain unauthorized access to other users' private message threads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203