Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8155

Опубликовано: 31 июл. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

EPSS

Процентиль: 4%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
github
3 дня назад

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.

EPSS

Процентиль: 4%
0.00138
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-639