CVE · Medium

CVE-2026-53675 — BuddyPress [buddypress] <= 14.4.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-53675 BuddyPress [buddypress] <= 14.4.0 (unfixed) Medium 4.3 < 14.4.0 14.4.0 2026-06-09

CVE-2026-53675

BuddyPress version 14.4.0 has a flaw in its friends REST API that lets anyone with an account access another user's entire friend list without their consent. This happens because the system doesn't check if the person requesting information is allowed to see it, only that they're logged in. As a result, users' private social connections are exposed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.