Impact
BuddyDev's Activity Plus Reloaded for BuddyPress plugin contains a missing authorization flaw that allows users to bypass configured access control levels. The defect lets authenticated users read or potentially alter activity data that should be restricted to higher‑privilege roles. This can expose private content, personal activity logs, and other protected information, compromising confidentiality and potentially enabling further malicious actions.
Affected Systems
The vulnerable component is the Activity Plus Reloaded for BuddyPress plugin, affecting all installations using version 1.1.2 or earlier on WordPress sites. The issue is tied to BuddyDev as the publisher. No other vendors or product variants are mentioned.
Risk and Exploitability
With a CVSS score of 5.4, the vulnerability is considered medium severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The flaw is likely exploitable by users who are already authenticated but do not have sufficient permission, by manipulating or accessing protected activity streams. No remote code execution or denial of service effect is reported, but the impact remains significant due to unauthorized data exposure.
OpenCVE Enrichment
EUVD