BuddyPress Member Reviews <= 3.8.0 - Unauthenticated Sensitive Information Exposure via Review Pages, Single Review View and Member Widgets

Medium 5.3 CWE-200Fixed in 3.8.1
ID
WPSEC-2026-0750
Plugin
Wbcom Designs – BuddyPress Member Reviews (bp-user-profile-reviews)
Affected
all versions before 3.8.1
Remediation
Update to 3.8.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
BuddyPress Member Reviews on WPSec AttackSurface
Fix released
Published

Description

The BuddyPress Member Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.0. The 'review' post type was registered as public with an archive, the single review view did not check the review's status or the member it belongs to, the avatar alt text on the single review page contained the reviewer's login name even for anonymous reviews, the Member Rating widget showed the real reviewer's avatar for anonymous reviews, and the top members output printed login usernames. This makes it possible for unauthenticated attackers to read pending or report-hidden reviews, identify the authors of anonymous reviews, and obtain member login names.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0