{"id":"CVE-2024-12145","title":"BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion","summary":"The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cvssSource":"cna","cwe":["CWE-862"],"vendor":"buddypress","product":"BuddyPress","affected":["BuddyPress <= 14.3.3"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T20:09:41.998791Z"},"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:19:12.097Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2024-12145","references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c2965c0-a07f-46a2-b06c-fa2e739aea94?source=cve"},{"url":"https://plugins.trac.wordpress.org/changeset/3259392/"}],"tags":["cve.org"],"epss":0.00201,"epssPercentile":0.10268,"ingestedAt":"2026-09-14T11:11:19.883Z","slug":"CVE-2024-12145","body":"## Overview\n\nThe BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users.\n\n## Affected\n\n- `BuddyPress <= 14.3.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}