HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-1360 — The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste...

·Source: NIST NVD

Updated:

Executive Summary

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar

Analysis

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment. CVSS Score: 7.5. Published: 2026-07-30T05:16:34.657.

Indicators of Compromise (1)

CVE (1)
CVE-2026-1360
Source Attribution

Originally published by NIST NVD on Jul 30, 2026. Verified by: NIST.

Related Threats