CVE-2026-1360

BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment.


We have discovered 8,382 live websites that are affected by CVE-2026-1360.

Run a Free Instant Scan




Affected Software

Product  BuddyPress
Category Message Boards
Vulnerable Domains8,382 live websites (100% of BuddyPress install base)
Vulnerable Versions
  • from 0 through 14.5
Vulnerable Versions Count102 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Vincent Theriault-Laine (finder)

Website Distribution by Country

Number of websites using CVE-2026-1360
United States2,986 websites



Germany725 websites
France572 websites
Italy386 websites
Russia337 websites
GB326 websites
Spain223 websites
Japan220 websites
Netherlands200 websites
Canada158 websites

Website Distribution by TLD

Number of websites using CVE-2026-1360
.com3,480 websites
.org941 websites
.de328 websites
.net305 websites
.ru281 websites
.it233 websites
.fr207 websites
.nl142 websites
.co.uk136 websites
.eu124 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1360

Top websites that are affected by CVE-2026-1360. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.*******.org United States**,***
********.fr France**,***
**********.org United States**,***
*******.com France**,***
***.org United States**,***
********************.org United States**,***
*************.org France**,***
*******************.com United States**,***
********.net United States***,***
********.hr Croatia***,***
See full domain list

FAQ

CVE-2026-1360 is Deserialization of Untrusted Data in BuddyPress
A total of 8,382 websites have been identified as vulnerable to CVE-2026-1360, based on global website indexing conducted by WebTechSurvey.
The BuddyPress is affected by the CVE-2026-1360 vulnerability.
BuddyPress versions up to and including 14.5 are vulnerable to CVE-2026-1360.

References