Deserialization Vulnerability in BuddyPress Plugin for WordPress
CVE-2026-1360
7.5HIGH
What is CVE-2026-1360?
The BuddyPress plugin for WordPress contains a vulnerability that allows authenticated users, starting from subscriber-level access, to inject arbitrary PHP objects through the XProfile textbox fields. This issue arises from the misuse of the @unserialize() function in the bp_unserialize_profile_field() method, which lacks the allowed_classes parameter. If exploited, this could lead to remote code execution under specific conditions, significantly compromising the web application’s security.
Affected Version(s)
BuddyPress 0 <= 14.5.0