---
id: CVE-2026-53675
title: >-
  BuddyPress 14.4.0 contains an insecure direct object reference vulnerability
  in the friends REST API that allows any authenticated attacker to enumerate
  another user's complete friend list
summary: >-
  BuddyPress 14.4.0 contains an insecure direct object reference vulnerability
  in the friends REST API that allows any authenticated attacker to enumerate
  another user's complete friend list. Attackers can query the friends endpoint
  with a…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: BuddyPress
product: BuddyPress
affected:
  - BuddyPress <= 14.4.0
published: '2026-06-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:19.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53675'
references:
  - url: 'https://buddypress.org/'
    label: disclosure@vulncheck.com
  - url: 'https://wordpress.org/plugins/buddypress/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/buddypress-friends-list-idor-via-rest-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-10T12:59:01.050346Z'
epss: 0.00389
epssPercentile: 0.3086
ingestedAt: '2026-10-08T16:52:14.686Z'
---

## Overview

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
