What is CVE-2026-8155?
The BuddyPress WordPress plugin before version 14.5.0 fails to properly enforce authorization on its private messaging endpoints, allowing any authenticated user with Subscriber+ role to read, modify, or delete other users' private messages. Immediate update to the latest version is strongly recommended to mitigate this vulnerability.
Azərbaycanca: BuddyPress WordPress plugini (14.5.0-dən əvvəlki versiyalarda) şəxsi mesajlaşma endpointlərində avtorizasiyanı düzgün tətbiq etmir, bu da hər hansı Subscriber+ səviyyəli autentifikasiya olunmuş istifadəçiyə digərlərinin şəxsi mesajlarını oxumağa, dəyişməyə və ya silməyə imkan yaradır. Təsirə məruz qalmamaq üçün plugini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-8155 and what is the safe version?
The vulnerability affects the BuddyPress WordPress plugin. To mitigate it, you need to update to version 14.5.0 or higher.
What level of account does an attacker need to exploit CVE-2026-8155?
The attacker needs to be an authenticated user with a Subscriber+ role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.