Impact
BuddyPress plugin suffers a missing authorization flaw that allows attackers to bypass normal access controls and perform privileged operations such as manipulating user data or altering site content, potentially compromising confidentiality and integrity. The weakness is categorized as CWE-862, a classic example of broken access control.
Affected Systems
Keyword "BuddyPress" refers to the WordPress BuddyPress plugin. All versions of the plugin up to and including 14.3.4 are affected. Users running any of these releases should evaluate their installation against the stated vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score of less than 1% suggests exploitation is unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via remote web requests using an authenticated user's session, where an attacker can craft requests to privileged endpoints that lack proper permission checks. Successful exploitation would elevate an attacker’s privileges within the WordPress environment.
OpenCVE Enrichment