BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking. | |
| Title | BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution | |
| First Time appeared |
Buddypress
Buddypress buddypress |
|
| Weaknesses | CWE-943 | |
| CPEs | cpe:2.3:a:buddypress:buddypress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Buddypress
Buddypress buddypress |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T23:44:21.471Z
Reserved: 2026-06-09T23:14:36.036Z
Link: CVE-2026-53674
No data.
Status : Received
Published: 2026-06-10T00:16:55.190
Modified: 2026-06-10T00:16:55.190
Link: CVE-2026-53674
No data.
OpenCVE Enrichment
Updated: 2026-06-10T02:45:15Z
Weaknesses