Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6pp9-x443-r8xw

Опубликовано: 31 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

EPSS

Процентиль: 4%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
nvd
3 дня назад

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

EPSS

Процентиль: 4%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639