SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-8155

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The BuddyPress plugin for WordPress prior to version 14.5.0 is vulnerable due to inadequate authorization enforcement on its private messaging endpoints, enabling any authenticated user with Subscriber privileges or higher to access, alter, or delete private messages belonging to other users. This could lead to unauthorized disclosure of sensitive information and potential data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-8155
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.