PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8155 BuddyPress CVE debrief

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. This issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639, indicating improper authorization. This could lead to unauthorized access or modification of sensitive information. Administrators of WordPress sites using the BuddyPress plugin should verify their version and consider upgrading to 14.5.0 or later. Additionally, security teams should monitor for potential data breaches, and users should be cautious about the privacy of their private messages. Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.

Vendor
BuddyPress
Product
BuddyPress WordPress plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-07-31
Advisory published
2026-07-31
Advisory updated
2026-07-31

Who should care

Administrators of WordPress sites using the BuddyPress plugin, security teams monitoring for potential data breaches, and users concerned about privacy of their private messages.

Technical summary

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints. This allows any authenticated user (Subscriber+) to read, modify, or delete other users' private messages. The issue has a CVSS score of 5.4 and is classified as MEDIUM severity. The vulnerability is characterized by CWE-639.

Defensive priority

Authenticated users may be able to access, alter, or remove private messages not intended for them, potentially leading to information disclosure or data tampering.

Recommended defensive actions

  • Inventory and verify BuddyPress plugin version
  • Restrict access to private messaging endpoints
  • Monitor for suspicious activity
  • Apply vendor patch or upgrade to version 14.5.0 or later
  • Review and update authorization controls

Evidence notes

Evidence is based on information from the NVD and a vulnerability report from WPScan. Further verification is needed to determine the full scope of affected systems and to confirm vendor remediation efforts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:28.593Z and has not been modified since then.