Description
The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users.
Published: 2026-09-11
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: notification manipulation
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from missing validation on the bp_notifications_action_bulk_manage endpoint, allowing an authenticated user with at least Subscriber privileges to target arbitrary notification identifiers. An attacker can delete, mark as read, or mark as unread notifications belonging to other users, representing a classic insecure direct object reference (CWE‑862). The impact is primarily privacy and availability of user notifications, with no escalation to broader system compromise noted.

Affected Systems

All releases of the BuddyPress plugin for WordPress up to and including version 14.3.3 are affected. Users operating any of these versions should update to version 14.3.4.

Risk and Exploitability

The CVSS score of 4.3 indicates a low overall risk, and the EPSS data is unavailable, suggesting a modest likelihood of exploitation. The flaw is not listed in CISA KEV. An attacker only needs to be authenticated with a role of Subscriber or higher and knowledge of the required. Hence, while exploitation is feasible, the attack surface is limited to the management of other users’ notifications rather than system-wide compromise.

Generated by OpenCVE AI on September 11, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BuddyPress to version 14.3.4 or newer to eliminate the validation flaw.
  • Restrict the bulk notifications operations for users with Subscriber role by applying a role‑management plugin or custom code.
  • Monitor notification activity for abnormal deletion or read‑mark patterns to detect potential misuse.

Generated by OpenCVE AI on September 11, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Buddypress
Buddypress buddypress
Wordpress
Wordpress wordpress
Vendors & Products Buddypress
Buddypress buddypress
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users.
Title BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Buddypress Buddypress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T11:28:52.377Z

Reserved: 2024-12-04T11:44:00.635Z

Link: CVE-2024-12145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:50.957

Modified: 2026-09-11T13:24:07.133

Link: CVE-2024-12145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T15:45:16Z

Weaknesses