CVE-2024-12145
Received Received - Intake

Authenticated IDOR in BuddyPress Allows Notification Manipulation

Vulnerability report for CVE-2024-12145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Wordfence

Description

The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete/mark as read/mark as unread notifications of other users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bp_theme buddypress to 14.3.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The BuddyPress plugin for WordPress has an Insecure Direct Object Reference vulnerability in versions up to 14.3.3. This flaw allows authenticated attackers with Subscriber-level access or higher to manipulate user notifications by deleting, marking as read, or marking as unread notifications belonging to other users. The issue occurs due to missing validation on a user-controlled key in the bp_notifications_action_bulk_manage function.

Impact Analysis

If you use a vulnerable version of the BuddyPress plugin, an attacker with minimal access could delete or alter your notifications without permission. This could disrupt your workflow, hide important updates, or cause confusion by changing notification states for other users.

Mitigation Strategies

Update the BuddyPress plugin to the latest version, which is 14.3.4 or higher, to address the insecure direct object reference vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-12145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart