plugin

Bp Profile Search Vulnerabilities

9 known security issues reported for the Bp Profile Search WordPress plugin. Most recent disclosed Aug 20, 2024.

1 critical 2 medium

Running Bp Profile Search on your site? Check whether your installed version is affected.

Scan your site free

BP Profile Search [bp-profile-search] < 5.8

unknown

[en] The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on the bps_ajax_field_selector(), bps_ajax_template_options(), and bps_ajax_field_row() functions. This makes it possible for unau...

Affected:
up to 5.8
Fixed in:
5.8
Disclosed:
Aug 20, 2024

CVE-2024-7850 on NVD →

BP Profile Search <= 5.7.5 - Cross-Site Request Forgery to Reflected Cross-Site Scripting

medium

The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on the bps_ajax_field_selector(), bps_ajax_template_options(), and bps_ajax_field_row() functions. This makes it possible for unauthent...

CVSS:
6.1
Affected:
up to 5.7.5
Fixed in:
5.8
Disclosed:
Aug 19, 2024

CVE-2024-7850 on NVD →

BP Profile Search [bp-profile-search] < 5.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Tarantini BP Profile Search allows Reflected XSS.This issue affects BP Profile Search: from n/a through 5.5.

Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Jan 31, 2024

CVE-2024-22293 on NVD →

BP Profile Search <= 5.5 - Reflected Cross-Site Scripting via BPS_FORM

medium

The BP Profile Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ BPS_FORM’ parameter in versions up to, and including, 5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 5.5
Fixed in:
5.6
Disclosed:
Jan 17, 2024

CVE-2024-22293 on NVD →

BP Profile Search [bp-profile-search] < 4.6

unknown

Update the plugin. Robert R discovered and reported this Arbitrary File Upload vulnerability in WordPress BP Profile Search Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability...

Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Dec 9, 2023

BP Profile Search <= 4.5.3 - PHP Object Injection

critical

The BP Profile Search plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.3 via deserialization of untrusted input from the vulnerable parameter 'bps_request'. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is p...

CVSS:
9
Affected:
up to 4.5.3
Fixed in:
4.6
Disclosed:
Dec 9, 2016

BP Profile Search [bp-profile-search] < 4.6

unknown

This plugin is prone to a PHP object injection vulnerability. Update the plugin.

Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Dec 9, 2016

BP Profile Search [bp-profile-search] < 4.6

unknown

The BP Profile Search plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.3 via deserialization of untrusted input from the vulnerable parameter 'bps_request'. This allows attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is p...

Affected:
up to 4.6
Fixed in:
4.6
Disclosed:
Dec 9, 2016

BP Profile Search [bp-profile-search] < 4.6

unknown

The plugin bp-profile-search insecurely trusts serialized data submitted over HTTP requests. This opens up the site to a PHP object injection vulnerability potential exploit vector. This vulnerability was patched in version 4.6, information is being released now as a disclosure period has expired.

Affected:
up to 4.6
Fixed in:
4.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database