CVE-2026-53673 | BuddyPress up to 14.4.0 Messages REST API get_item_permissions_check user_id authorization
A vulnerability was found in BuddyPress up to 14.4.0. It has been rated as critical. This issue affects the function get_item_permissions_check of the component Messages REST API. The manipulation of the argument user_id leads to authorization bypass.
This vulnerability is referenced as CVE-2026-53673. Remote exploitation of the attack is possible. No exploit is available.