# BuddyPress Member Reviews <= 3.8.0 - Unauthenticated Sensitive Information Exposure via Review Pages, Single Review View and Member Widgets

- **ID:** WPSEC-2026-0750
- **Plugin:** Wbcom Designs – BuddyPress Member Reviews (`bp-user-profile-reviews`), https://wordpress.org/plugins/bp-user-profile-reviews/
- **Affected versions:** all versions before 3.8.1
- **Fixed in:** 3.8.1 (Update to 3.8.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/bp-user-profile-reviews
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0750/

## Description

The BuddyPress Member Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.0. The 'review' post type was registered as public with an archive, the single review view did not check the review's status or the member it belongs to, the avatar alt text on the single review page contained the reviewer's login name even for anonymous reviews, the Member Rating widget showed the real reviewer's avatar for anonymous reviews, and the top members output printed login usernames. This makes it possible for unauthenticated attackers to read pending or report-hidden reviews, identify the authors of anonymous reviews, and obtain member login names.

## References

- https://wpsec.com/vuln/WPSEC-2026-0750/
- https://plugins.svn.wordpress.org/bp-user-profile-reviews/tags/3.8.1/
- https://wordpress.org/plugins/bp-user-profile-reviews/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0750/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
