CyberRota Analysis
AI-GeneratedThe BuddyPress plugin for WordPress prior to version 14.5.0 is vulnerable due to inadequate authorization enforcement on its private messaging endpoints, enabling any authenticated user with Subscriber privileges or higher to access, alter, or delete private messages belonging to other users. This could lead to unauthorized disclosure of sensitive information and potential data manipulation. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.