The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment.
We have discovered 8,382 live websites that are affected by CVE-2026-1360.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 8,382 live websites (100% of BuddyPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 102 versions ( 100% of all versions) |
| 2,986 websites | |
| 725 websites | |
| 572 websites | |
| 386 websites | |
| 337 websites | |
| 326 websites | |
| 223 websites | |
| 220 websites | |
| 200 websites | |
| 158 websites |
| .com | 3,480 websites |
| .org | 941 websites |
| .de | 328 websites |
| .net | 305 websites |
| .ru | 281 websites |
| .it | 233 websites |
| .fr | 207 websites |
| .nl | 142 websites |
| .co.uk | 136 websites |
| .eu | 124 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.*******.org | **,*** | ||
| ********.fr | **,*** | ||
| **********.org | **,*** | ||
| *******.com | **,*** | ||
| ***.org | **,*** | ||
| ********************.org | **,*** | ||
| *************.org | **,*** | ||
| *******************.com | **,*** | ||
| ********.net | ***,*** | ||
| ********.hr | ***,*** |
FAQ