CVE-2026-53674
HIGHBuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
Title source: cnaDescription
BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.
References (3)
Core 3
Core References
Product product
https://buddypress.org/
Product product
https://wordpress.org/plugins/buddypress/
Third Party Advisory third-party-advisory
VulnCheck Advisory: BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
https://www.vulncheck.com/advisories/buddypress-regexp-injection-via-mention-username-resolution
Scores
CVSS v3
7.1
EPSS
0.0029
EPSS Percentile
20.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-943
Status
published
Products (1)
BuddyPress/BuddyPress
< 14.4.0
Published
Jun 10, 2026
Tracked Since
Jun 10, 2026