Impact
The vulnerability arises from missing validation on the bp_notifications_action_bulk_manage endpoint, allowing an authenticated user with at least Subscriber privileges to target arbitrary notification identifiers. An attacker can delete, mark as read, or mark as unread notifications belonging to other users, representing a classic insecure direct object reference (CWE‑862). The impact is primarily privacy and availability of user notifications, with no escalation to broader system compromise noted.
Affected Systems
All releases of the BuddyPress plugin for WordPress up to and including version 14.3.3 are affected. Users operating any of these versions should update to version 14.3.4.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall risk, and the EPSS data is unavailable, suggesting a modest likelihood of exploitation. The flaw is not listed in CISA KEV. An attacker only needs to be authenticated with a role of Subscriber or higher and knowledge of the required. Hence, while exploitation is feasible, the attack surface is limited to the management of other users’ notifications rather than system-wide compromise.
OpenCVE Enrichment