{"id":"GHSA-j3j5-5m8v-7gvc","summary":"BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter","details":"BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.","aliases":["CVE-2026-53673"],"modified":"2026-09-10T03:50:49.885985696Z","published":"2026-06-10T00:31:53Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-12T18:47:41Z","nvd_published_at":"2026-06-10T00:16:55Z","cwe_ids":["CWE-639"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53673"},{"type":"WEB","url":"https://github.com/buddypress/buddypress/commit/27d41e9749a878103b3a673b37dfc92b7f8f2cb7"},{"type":"WEB","url":"https://buddypress.org"},{"type":"PACKAGE","url":"https://github.com/buddypress/BuddyPress"},{"type":"WEB","url":"https://wordpress.org/plugins/buddypress"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/buddypress-private-message-idor-via-rest-api-user-id-parameter"}],"affected":[{"package":{"name":"buddypress/buddypress","ecosystem":"Packagist","purl":"pkg:composer/buddypress/buddypress"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.5.0"}]}],"versions":["10.0.0","10.0.0-RC1","10.0.0-beta1","10.0.0-beta2","10.1.0","10.2.0","10.3.0","10.4.0","10.5.0","10.6.0","10.6.1","10.6.2","10.6.3","10.6.4","11.0.0","11.0.0-RC1","11.0.0-beta1","11.0.0-beta2","11.0.0-beta3","11.1.0","11.2.0","11.3.1","11.3.2","11.4.0","11.4.0-beta1","11.4.1","11.4.2","11.4.3","11.4.4","11.5.1","11.5.2","11.6.0","11.6.2","12.0.0","12.0.0-RC1","12.0.0-beta1","12.0.0-beta2","12.0.0-beta3","12.0.0-beta4","12.1.1","12.2.0","12.3.0","12.4.0","12.4.1","12.5.0","12.5.1","12.5.2","12.5.3","12.6.0","12.7.0","12.7.2","14.0.0","14.0.0-RC1","14.0.0-beta1","14.0.0-beta2","14.1.0","14.2.1","14.3.1","14.3.3","14.3.4","14.4.0","2.2-beta1","2.2-beta2","2.2-rc1","2.2-rc2","2.2.0","2.2.1","2.2.2","2.2.2.1","2.2.3","2.2.3.1","2.2.4","2.2.5","2.2.6","2.3.0","2.3.0-beta-2","2.3.0-beta1","2.3.0-rc1","2.3.1","2.3.2","2.3.2.1","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.0-beta1","2.4.0-beta2","2.4.0-rc1","2.4.2","2.4.3","2.4.4","2.4.5","2.5.0","2.5.0-beta1","2.5.0-rc1","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6.0","2.6.0-beta1","2.6.0-rc1","2.6.1","2.6.1.1","2.6.2","2.6.3","2.6.4","2.7.0","2.7.0-beta1","2.7.0-rc1","2.7.0-rc2","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0","2.8.0-RC1","2.8.0-beta1","2.8.1","2.8.2","2.9.0","2.9.0-RC1","2.9.0-beta2","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5.1","3.0.0","3.0.0-RC2","3.0.0-beta1","3.0.0-beta2","3.1.0","3.2.0","3.2.1","4.0.0","4.0.0-RC1","4.0.0-beta1","4.1.0","4.2.0","4.3.0","4.4.0","4.4.1","5.0.0","5.0.0-RC1","5.0.0-RC2","5.0.0-beta1","5.0.0-beta2","5.1.0","5.1.0-beta1","5.1.1","5.1.2","5.2.0","5.2.1","5.2.2","6.0.0","6.0.0-RC1","6.0.0-RC2","6.0.0-beta1","6.0.0-beta2","6.1.0","6.2.0","6.2.0-beta1","6.3.0","6.4.0","6.4.2","6.4.3","7.0.0","7.0.0-RC1","7.0.0-RC2","7.0.0-beta1","7.0.0-beta2","7.1.0","7.2.0","7.2.1","7.3.0","7.3.2","7.3.3","7.3.4","8.0.0","8.0.0-RC1","8.0.0-beta1","8.0.0-beta2","8.0.2","8.0.3","8.0.4","9.0.0","9.0.0-RC1","9.1.1","9.2.0","9.2.1","9.2.2","9.2.3","9.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-j3j5-5m8v-7gvc/GHSA-j3j5-5m8v-7gvc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}