BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections. | |
| Title | BuddyPress 14.4.0 Friends List IDOR via REST API | |
| First Time appeared |
Buddypress
Buddypress buddypress |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:buddypress:buddypress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Buddypress
Buddypress buddypress |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T23:44:22.188Z
Reserved: 2026-06-09T23:14:36.037Z
Link: CVE-2026-53675
No data.
Status : Received
Published: 2026-06-10T00:16:55.323
Modified: 2026-06-10T00:16:55.323
Link: CVE-2026-53675
No data.
OpenCVE Enrichment
Updated: 2026-06-10T01:45:18Z