CVE-2026-53673 - BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter
CVE ID :CVE-2026-53673 Published : June 10, 2026, 12:16 a.m. | 58 minutes ago Description :BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a...