CVE-2026-8155: BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
Published Jul 31, 2026
·Updated
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
Affected Software
1 affected component
BuddyPress BuddyPress<14.5.0
Event History
Jul 31, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-8155?
CVE-2026-8155 has a risk rating of 62, indicating a moderate level of severity.
2
How do I fix CVE-2026-8155?
To mitigate CVE-2026-8155, update the BuddyPress plugin to version 14.5.0 or later.
3
What type of vulnerability is CVE-2026-8155?
CVE-2026-8155 is an Insecure Direct Object Reference (IDOR) vulnerability affecting private messaging in BuddyPress.
4
Who is affected by CVE-2026-8155?
Any authenticated user with Subscriber+ roles can exploit CVE-2026-8155 to access private messages of other users.
5
When was CVE-2026-8155 published?
CVE-2026-8155 was published on July 31, 2026.