CyberRota
← Ana sayfaya dön

CVE-2026-53673

HIGH · CVSS 8.1 EPSS %0.29

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-10T00:16:55.040 · Çekilme zamanı: 2026-06-30T12:15:51.750380+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-53673
Severity
HIGH
CVSS
8.1
EPSS
%0.29

Orijinal NVD Açıklaması

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.