{
 "id": "WPSEC-2026-0750",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0750/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0750/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0750/index.md",
 "title": "BuddyPress Member Reviews <= 3.8.0 - Unauthenticated Sensitive Information Exposure via Review Pages, Single Review View and Member Widgets",
 "description": "The BuddyPress Member Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.0. The 'review' post type was registered as public with an archive, the single review view did not check the review's status or the member it belongs to, the avatar alt text on the single review page contained the reviewer's login name even for anonymous reviews, the Member Rating widget showed the real reviewer's avatar for anonymous reviews, and the top members output printed login usernames. This makes it possible for unauthenticated attackers to read pending or report-hidden reviews, identify the authors of anonymous reviews, and obtain member login names.",
 "plugin": {
  "slug": "bp-user-profile-reviews",
  "name": "BuddyPress Member Reviews",
  "full_name": "Wbcom Designs – BuddyPress Member Reviews",
  "wordpress_org": "https://wordpress.org/plugins/bp-user-profile-reviews/",
  "advisories_url": "https://wpsec.com/vuln/plugin/bp-user-profile-reviews/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/bp-user-profile-reviews"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.8.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.8.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.8.1",
 "remediation": "Update to 3.8.1 or later.",
 "fix_released": "2026-10-09T10:52:53+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:54:05.077689+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0750/",
  "https://plugins.svn.wordpress.org/bp-user-profile-reviews/tags/3.8.1/",
  "https://wordpress.org/plugins/bp-user-profile-reviews/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/bp-user-profile-reviews",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-10"
 }
}