PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8155 BuddyPress CVE debrief

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. This issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639, indicating improper authorization. This could lead to unauthorized access or modification of sensitive information. Administrators of WordPress sites using the BuddyPress plugin should verify their version and consider upgrading to 14.5.0 or later. Additionally, security teams should monitor for potential data breaches, and users should be cautious about the privacy of their private messages. Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.

Vendor
BuddyPress
Product
BuddyPress WordPress plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-08-26
Advisory published
2026-07-31
Advisory updated
2026-08-26

Who should care

Administrators of WordPress sites using the BuddyPress plugin, security teams monitoring for potential data breaches, and users concerned about privacy of their private messages.

Technical summary

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints. This allows any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. The issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639.

Defensive priority

Authenticated users may be able to access, alter, or remove private messages not intended for them, potentially leading to information disclosure or data tampering.

Recommended defensive actions

  • Inventory and verify BuddyPress plugin version
  • Restrict access to private messaging endpoints
  • Monitor for suspicious activity
  • Apply vendor patch or upgrade to version 14.5.0 or later
  • Review and update authorization controls

Evidence notes

Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8155 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8155

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8155 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8155

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.