Home

Description

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.

PUBLISHED Reserved 2026-06-09 | Published 2026-06-09 | Updated 2026-06-10 | Assigner VulnCheck




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Problem types

Improper Neutralization of Special Elements in Data Query Logic

Product status

Any version
affected

Credits

Scott Moore - VulnCheck finder

References

buddypress.org/ product

wordpress.org/plugins/buddypress/ product

www.vulncheck.com/...jection-via-mention-username-resolution (VulnCheck Advisory: BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution) third-party-advisory

cve.org (CVE-2026-53674)

nvd.nist.gov (CVE-2026-53674)

Download JSON