VYPR
High severity7.1NVD Advisory· Published Jun 10, 2026

CVE-2026-53674

CVE-2026-53674

Description

BuddyPress 14.4.0 has a regex injection flaw in its activity mention resolver, allowing username inference and DoS when compatibility mode is enabled.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BuddyPress 14.4.0 has a regex injection flaw in its activity mention resolver, allowing username inference and DoS when compatibility mode is enabled.

Vulnerability

BuddyPress versions 14.4.0 and earlier contain a regular expression injection vulnerability within the activity mention resolver. This vulnerability is exploitable when username compatibility mode is enabled. Attackers can craft mention names containing regex metacharacters, which are then inserted into an unprepared REGEXP query against the users table without proper escaping [1].

Exploitation

An attacker needs to be able to submit a crafted @mention. By including regular expression metacharacters within the mention name, the attacker can manipulate the REGEXP database clause. These metacharacters are not properly escaped by esc_sql and are directly incorporated into the SQL query, leading to the vulnerability [1].

Impact

Successful exploitation allows an attacker to perform boolean-based inference of usernames. Additionally, the vulnerability can lead to a denial of service through catastrophic backtracking within the regular expression engine [1].

Mitigation

BuddyPress 14.5.0, released on 2024-04-03, addresses this vulnerability. Users are strongly recommended to update to version 14.5.0 or later immediately. No workarounds are available other than updating the plugin [1].

References
  1. BuddyPress

AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.