BuddyPress has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 4.3 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Worst active — by depth score
CVE-2026-53673High· 8.1BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request45CVE-2024-12145Medium· 4.3BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion24CVE-2026-53675Medium· 4.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list24
BuddyPress vulnerabilities
CVEs affecting BuddyPress, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2024-12145Medium· 4.3BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion
The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes…
CVE-2026-53675Medium· 4.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with a…
CVE-2026-53673High· 8.1BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attack…