Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
CVE-2026-8155
Description
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/b7dd9cbf-b46b-49ee-84a0-6b054676fccb/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.