CVE-2026-53675: BuddyPress 14.4.0 Friends List IDOR via REST API

Published Jun 9, 2026
·
Updated

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary userid because the getitemspermissionscheck method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

Affected Software

1 affected component
BuddyPress BuddyPress=14.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove BuddyPress 14.4.0 from your environment.

    If BuddyPress (or its Friends component) is not required, uninstall or deactivate BuddyPress or disable the Friends component/module until an official fix is released to eliminate exposure from the vulnerable REST API.

  2. Compensating control

    Block or restrict access to the BuddyPress friends REST API endpoints until a vendor patch is available. Implement a WAF rule, reverse-proxy rule, or firewall/ACL to prevent authenticated users from querying arbitrary friends endpoints (e.g., filter or deny requests that include friends endpoint paths or requests that specify arbitrary user_id values).

Event History

Jun 9, 2026
CVE Published
via MITRE·11:44 PM
Data Sourced
via MITRE·11:44 PM
DescriptionSeverityWeakness
Jun 10, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-53675?

CVE-2026-53675 has a medium severity rating of 5.3.

2

How can I fix CVE-2026-53675?

To fix CVE-2026-53675, update BuddyPress to the latest version that addresses the friends REST API vulnerability.

3

What type of vulnerability is CVE-2026-53675?

CVE-2026-53675 is classified as an insecure direct object reference (IDOR) vulnerability.

4

Who is affected by CVE-2026-53675?

Any authenticated user of BuddyPress 14.4.0 can potentially exploit CVE-2026-53675 to access another user's friend list.

5

What can an attacker do with CVE-2026-53675?

An attacker can use CVE-2026-53675 to enumerate the complete friend list of any user by manipulating the user_id in the friends REST API.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203