CVE-2026-53674

HIGH

BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution

Title source: cna
STIX 2.1

Description

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.

References (3)

Core 3
Core References
Product product
https://buddypress.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
https://www.vulncheck.com/advisories/buddypress-regexp-injection-via-mention-username-resolution

Scores

CVSS v3 7.1
EPSS 0.0029
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-943
Status published
Products (1)
BuddyPress/BuddyPress < 14.4.0
Published Jun 10, 2026
Tracked Since Jun 10, 2026