plugin

Activity Reactions For Buddypress Vulnerabilities

6 known security issues reported for the Activity Reactions For Buddypress WordPress plugin. Most recent disclosed Apr 17, 2025.

1 high 2 medium

Running Activity Reactions For Buddypress on your site? Check whether your installed version is affected.

Scan your site free

Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Activity Reactions For Buddypress allows Reflected XSS. This issue affects Activity Reactions For Buddypress: from n/a through 1.0.22.

Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Apr 17, 2025

CVE-2025-31006 on NVD →

Activity Reactions For Buddypress <= 1.0.22 - Reflected Cross-Site Scripting

medium

The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
6.1
Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-31006 on NVD →

Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.

Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Apr 23, 2023

CVE-2022-45074 on NVD →

Activity Reactions For Buddypress <= 1.0.22 - Cross-Site Request Forgery

high

The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.22. This is due to missing nonce validation on the ai_front_smiley() function. This makes it possible for unauthenticated attackers to disabled and enable reactions granted they c...

CVSS:
8.8
Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Nov 11, 2022

CVE-2022-45074 on NVD →

Activity Reactions For Buddypress <= 1.0.22 - Missing Authorization

medium

The Activity Reactions For Buddypress plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 1.0.22 on the ai_front_smiley function. This makes it possible for subscriber-level to enable and disable reactions.

CVSS:
5.4
Affected:
up to 1.0.22
Fix:
No patched version reported
Disclosed:
Nov 11, 2022

CVE-2022-45075 on NVD →

Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.0.22
Fix:
No patched version reported

CVE-2022-45075 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database