Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arete-it Activity Reactions For Buddypress allows Reflected XSS. This issue affects Activity Reactions For Buddypress: from n/a through 1.0.22.
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-31006 on NVD →
Activity Reactions For Buddypress <= 1.0.22 - Reflected Cross-Site Scripting
medium
The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2025-31006 on NVD →
Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 versions.
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Apr 23, 2023
CVE-2022-45074 on NVD →
Activity Reactions For Buddypress <= 1.0.22 - Cross-Site Request Forgery
high
The Activity Reactions For Buddypress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.22. This is due to missing nonce validation on the ai_front_smiley() function. This makes it possible for unauthenticated attackers to disabled and enable reactions granted they c...
- CVSS:
- 8.8
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2022
CVE-2022-45074 on NVD →
Activity Reactions For Buddypress <= 1.0.22 - Missing Authorization
medium
The Activity Reactions For Buddypress plugin for WordPress is vulnerable to missing authorization checks in versions up to, and including, 1.0.22 on the ai_front_smiley function. This makes it possible for subscriber-level to enable and disable reactions.
- CVSS:
- 5.4
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2022
CVE-2022-45075 on NVD →
Activity Reactions For Buddypress [activity-reactions-for-buddypress] <= 1.0.22 (unfixed + closed)
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.0.22
- Fix:
- No patched version reported
CVE-2022-45075 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database