Insecure Direct Object Reference in BuddyPress Plugin by WordPress
CVE-2024-12145
4.3MEDIUM
What is CVE-2024-12145?
The BuddyPress plugin for WordPress contains a vulnerability that allows authenticated users with Subscriber-level access and higher to exploit the bp_notifications_action_bulk_manage function. Due to insufficient validation of user-controlled input, attackers can manipulate other users' notifications—deleting them, or modifying their read/unread status. This flaw highlights the importance of ensuring proper validation mechanisms to safeguard user data against unauthorized modifications.
Affected Version(s)
BuddyPress 0 <= 14.3.3