BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter (CVE-2026-53673)
BuddyPress versions prior to 14.5.0 contain an insecure direct object reference vulnerability in the messages REST API. Authenticated attackers can exploit this flaw by supplying a user_id parameter to access arbitrary private message threads belonging to other users. This vulnerability allows attackers to read, reply to, or delete any user's private messages without proper authorization.
AI Analysis
Technical Summary
CVE-2026-53673 is an insecure direct object reference (CWE-639) vulnerability in BuddyPress 14.4.0 and earlier versions. The flaw exists in the messages REST API where the get_item_permissions_check method validates the user_id parameter supplied by the attacker instead of the logged-in user's identity. This improper validation is reused by update and delete handlers, enabling authenticated attackers to access and manipulate private message threads of arbitrary users by passing their user_id in requests.
Potential Impact
Successful exploitation allows an authenticated attacker to gain unauthorized access to private message threads of other users, including reading, replying to, and deleting messages. This compromises the confidentiality and integrity of private communications within BuddyPress, potentially leading to privacy violations and unauthorized message manipulation.
Mitigation Recommendations
A patch is available that fixes this vulnerability. Users should upgrade BuddyPress to version 14.5.0 or later to remediate this issue. Until patched, restrict access to the messages REST API to trusted users only, if possible.
BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter (CVE-2026-53673)
Description
BuddyPress versions prior to 14.5.0 contain an insecure direct object reference vulnerability in the messages REST API. Authenticated attackers can exploit this flaw by supplying a user_id parameter to access arbitrary private message threads belonging to other users. This vulnerability allows attackers to read, reply to, or delete any user's private messages without proper authorization.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-53673 is an insecure direct object reference (CWE-639) vulnerability in BuddyPress 14.4.0 and earlier versions. The flaw exists in the messages REST API where the get_item_permissions_check method validates the user_id parameter supplied by the attacker instead of the logged-in user's identity. This improper validation is reused by update and delete handlers, enabling authenticated attackers to access and manipulate private message threads of arbitrary users by passing their user_id in requests.
Potential Impact
Successful exploitation allows an authenticated attacker to gain unauthorized access to private message threads of other users, including reading, replying to, and deleting messages. This compromises the confidentiality and integrity of private communications within BuddyPress, potentially leading to privacy violations and unauthorized message manipulation.
Mitigation Recommendations
A patch is available that fixes this vulnerability. Users should upgrade BuddyPress to version 14.5.0 or later to remediate this issue. Until patched, restrict access to the messages REST API to trusted users only, if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j3j5-5m8v-7gvc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53673"]
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7cd3e2bf8831d53917ff05
Added to database: 08/12/2026, 20:13:22 UTC
Last enriched: 08/12/2026, 20:56:51 UTC
Last updated: 09/23/2026, 01:47:43 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.