GHSA-wmjr-58rf-xgrc

Suggest an improvement
Source
https://github.com/advisories/GHSA-wmjr-58rf-xgrc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-wmjr-58rf-xgrc/GHSA-wmjr-58rf-xgrc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wmjr-58rf-xgrc
Aliases
  • CVE-2026-53675
Published
2026-06-10T00:31:53Z
Modified
2026-09-10T03:50:50Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
BuddyPress: Any authenticated attacker can enumerate another user's complete friend list via IDOR
Details

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

Database specific
{
    "cwe_ids":  [
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-12T19:13:35Z",
    "nvd_published_at":  "2026-06-10T00:16:55Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / buddypress/buddypress

Package

Name
buddypress/buddypress
Purl
pkg:composer/buddypress/buddypress

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
14.4.0

Affected versions

2.*
2.2-beta1
2.2-beta2
2.2-rc1
2.2-rc2
2.2.0
2.2.1
2.2.2
2.2.2.1
2.2.3
2.2.3.1
2.2.4
2.2.5
2.2.6
2.3.0-beta1
2.3.0-beta-2
2.3.0-rc1
2.3.0
2.3.1
2.3.2
2.3.2.1
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0-beta1
2.4.0-beta2
2.4.0-rc1
2.4.0
2.4.2
2.4.3
2.4.4
2.4.5
2.5.0-beta1
2.5.0-rc1
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.6.0-beta1
2.6.0-rc1
2.6.0
2.6.1
2.6.1.1
2.6.2
2.6.3
2.6.4
2.7.0-beta1
2.7.0-rc1
2.7.0-rc2
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.8.0-beta1
2.8.0-RC1
2.8.0
2.8.1
2.8.2
2.9.0-beta2
2.9.0-RC1
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5.1
3.*
3.0.0-beta1
3.0.0-beta2
3.0.0-RC2
3.0.0
3.1.0
3.2.0
3.2.1
4.*
4.0.0-beta1
4.0.0-RC1
4.0.0
4.1.0
4.2.0
4.3.0
4.4.0
4.4.1
5.*
5.0.0-beta1
5.0.0-beta2
5.0.0-RC1
5.0.0-RC2
5.0.0
5.1.0-beta1
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
6.*
6.0.0-beta1
6.0.0-beta2
6.0.0-RC1
6.0.0-RC2
6.0.0
6.1.0
6.2.0-beta1
6.2.0
6.3.0
6.4.0
6.4.2
6.4.3
7.*
7.0.0-beta1
7.0.0-beta2
7.0.0-RC1
7.0.0-RC2
7.0.0
7.1.0
7.2.0
7.2.1
7.3.0
7.3.2
7.3.3
7.3.4
8.*
8.0.0-beta1
8.0.0-beta2
8.0.0-RC1
8.0.0
8.0.2
8.0.3
8.0.4
9.*
9.0.0-RC1
9.0.0
9.1.1
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
10.*
10.0.0-beta1
10.0.0-beta2
10.0.0-RC1
10.0.0
10.1.0
10.2.0
10.3.0
10.4.0
10.5.0
10.6.0
10.6.1
10.6.2
10.6.3
10.6.4
11.*
11.0.0-beta1
11.0.0-beta2
11.0.0-beta3
11.0.0-RC1
11.0.0
11.1.0
11.2.0
11.3.1
11.3.2
11.4.0-beta1
11.4.0
11.4.1
11.4.2
11.4.3
11.4.4
11.5.1
11.5.2
11.6.0
11.6.2
12.*
12.0.0-beta1
12.0.0-beta2
12.0.0-beta3
12.0.0-beta4
12.0.0-RC1
12.0.0
12.1.1
12.2.0
12.3.0
12.4.0
12.4.1
12.5.0
12.5.1
12.5.2
12.5.3
12.6.0
12.7.0
12.7.2
14.*
14.0.0-beta1
14.0.0-beta2
14.0.0-RC1
14.0.0
14.1.0
14.2.1
14.3.1
14.3.3
14.3.4
14.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-wmjr-58rf-xgrc/GHSA-wmjr-58rf-xgrc.json"