CVE-2026-53675
Published
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.
<p>Are you looking for modern, robust, and sophisticated social network software? BuddyPress is a suite of components that are common to a typical social network, and allows for great add-on features through WordPress’s extensive plugin system.</p>
<p>Aimed at site builders & developers, BuddyPress is focused on ease of integration, ease of use, and extensibility. It is deliberately powerful yet unbelievably simple social network software, built by contributors to WordPress.</p>
<p><iframe loading="lazy" title="VideoPress Video Player" aria-label="VideoPress Video Player" width="750" height="422" src="https://video.wordpress.com/embed/wvvZgNwo?hd=1&cover=1" frameborder="0" allowfullscreen allow="clipboard-write"></iframe><script src='https://v0.wordpress.com/js/next/videopress-iframe.js?m=1770107250'></script></p>
<p>Members can register on your site to create user profiles, have private conversations, make social connections, create and interact in groups, and much more. Truly a social network in a box, BuddyPress helps you build a home for your company, school, sports team, or other niche community.</p>
<h4>Built with developers in mind</h4>
<p>BuddyPress helps site builders & developers add community features to their websites. It comes with a robust theme compatibility API that does its best to make every BuddyPress content page look and feel right with just about any WordPress theme. You will likely need to adjust some styling on your own to make everything look pristine.</p>
<p>BuddyPress themes are just WordPress themes with additional templates, and with a little work, you could easily create your own, too! A handful of BuddyPress-specific themes are readily available for download from WordPress.org, and lots more are available from third-party theme authors.</p>
<p>BuddyPress also comes with built-in support for Akismet and <a href="https://wordpress.org/plugins/bbpress/" rel="ugc">bbPress</a>, two very popular and very powerful WordPress plugins. If you’re using either, visit their settings pages and ensure everything is configured to your liking.</p>
<h4>The BuddyPress Add-ons</h4>
<p>WordPress.org is home to some amazing Add-ons for BuddyPress, including:</p>
<ul>
<li><a href="https://wordpress.org/plugins/bp-attachments/" rel="ugc">BP Attachments</a></li>
<li><a href="https://wordpress.org/plugins/bp-classic/" rel="ugc">BP Classic</a></li>
</ul>
<p><strong>NB</strong>: BP Classic is a backwards compatibility Add-on for BuddyPress 12.0 and up bringing back the BP Legacy URL parser, the BP Default theme and BP Legacy widgets.</p>
<p>Go to <a href="https://profiles.wordpress.org/buddypress/" rel="nofollow ugc">BuddyPress profile on WordPress.org</a> to find them all!</p>
<h4>Join our community</h4>
<p>If you’re interested in contributing to BuddyPress, we’d love to have you. Head over to the <a href="https://codex.buddypress.org/participate-and-contribute/" rel="nofollow ugc">BuddyPress Documentation</a> site to find out how you can pitch in.</p>
<p>BuddyPress is available in many languages thanks to the volunteer efforts of individuals all around the world. Check out our <a href="https://codex.buddypress.org/translations/" rel="nofollow ugc">translations page</a> on the BuddyPress Documentation site for more details. If you are a polyglot, please <a href="https://translate.wordpress.org/projects/wp-plugins/buddypress" rel="nofollow ugc">consider helping translate BuddyPress</a> into your language.</p>
<p>Growing the BuddyPress community means better software for everyone!</p>