BuddyPress Member Reviews <= 3.8.0 - Unauthenticated Sensitive Information Exposure via Review Pages, Single Review View and Member Widgets
- ID
- WPSEC-2026-0750
- Plugin
- Wbcom Designs – BuddyPress Member Reviews (bp-user-profile-reviews)
- Affected
- all versions before 3.8.1
- Remediation
- Update to 3.8.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- BuddyPress Member Reviews on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyPress Member Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.0. The 'review' post type was registered as public with an archive, the single review view did not check the review's status or the member it belongs to, the avatar alt text on the single review page contained the reviewer's login name even for anonymous reviews, the Member Rating widget showed the real reviewer's avatar for anonymous reviews, and the top members output printed login usernames. This makes it possible for unauthenticated attackers to read pending or report-hidden reviews, identify the authors of anonymous reviews, and obtain member login names.
References
- https://wpsec.com/vuln/WPSEC-2026-0750/
- https://plugins.svn.wordpress.org/bp-user-profile-reviews/tags/3.8.1/
- https://wordpress.org/plugins/bp-user-profile-reviews/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS