PatchSiren cyber security CVE debrief
CVE-2026-8155 BuddyPress CVE debrief
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. This issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639, indicating improper authorization. This could lead to unauthorized access or modification of sensitive information. Administrators of WordPress sites using the BuddyPress plugin should verify their version and consider upgrading to 14.5.0 or later. Additionally, security teams should monitor for potential data breaches, and users should be cautious about the privacy of their private messages. Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.
- Vendor
- BuddyPress
- Product
- BuddyPress WordPress plugin
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators of WordPress sites using the BuddyPress plugin, security teams monitoring for potential data breaches, and users concerned about privacy of their private messages.
Technical summary
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints. This allows any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. The issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639.
Defensive priority
Authenticated users may be able to access, alter, or remove private messages not intended for them, potentially leading to information disclosure or data tampering.
Recommended defensive actions
- Inventory and verify BuddyPress plugin version
- Restrict access to private messaging endpoints
- Monitor for suspicious activity
- Apply vendor patch or upgrade to version 14.5.0 or later
- Review and update authorization controls
Evidence notes
Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.
Official resources
-
CVE-2026-8155 CVE record
CVE.org
-
CVE-2026-8155 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:28.593Z and has not been modified since then.