plugin

Buddyboss Platform Vulnerabilities

17 known security issues reported for the Buddyboss Platform WordPress plugin. Most recent disclosed Jul 9, 2026.

1 critical 7 high 7 medium

Running Buddyboss Platform on your site? Check whether your installed version is affected.

Scan your site free

BuddyBoss Platform <= 3.0.5 - Unauthenticated SQL Injection

high

The BuddyBoss Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queri...

CVSS:
7.5
Affected:
up to 3.0.5
Fixed in:
3.1.0
Disclosed:
Jul 9, 2026

CVE-2026-59514 on NVD →

BuddyBoss Platform <= 3.0.4 - Authenticated (Subscriber+) PHP Object Injection

high

The BuddyBoss Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulne...

CVSS:
7.5
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Jun 23, 2026

CVE-2026-56032 on NVD →

BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'

medium

The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 2.8.50
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13858 on NVD →

BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'

medium

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above...

CVSS:
6.4
Affected:
up to 2.8.50
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13860 on NVD →

BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function

medium

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
6.4
Affected:
up to 2.8.50
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13859 on NVD →

BuddyBoss Platform < 2.8.51 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function

high
Affected:
up to 2.8.51
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13859 on NVD →

BuddyBoss Platform < 2.8.51 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'

high
Affected:
up to 2.8.51
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13860 on NVD →

BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'

high
Affected:
up to 2.8.51
Fixed in:
2.8.51
Disclosed:
May 1, 2025

CVE-2024-13858 on NVD →

BuddyBoss Platform <= 2.7.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'

medium

The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
6.4
Affected:
up to 2.7.70
Fixed in:
2.8.00
Disclosed:
Feb 26, 2025

CVE-2024-13402 on NVD →

BuddyBoss Platform < 2.8.00 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'

high
Affected:
up to 2.8.00
Fixed in:
2.8.00
Disclosed:
Feb 26, 2025

CVE-2024-13402 on NVD →

BuddyBoss Platform < 2.7.60 - Insecure Direct Object Reference to Private Post Comment Exposure

medium

The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.60 (exclusive) due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on private posts.

CVSS:
4.3
Affected:
up to 2.7.60
Fixed in:
2.7.60
Disclosed:
Jan 14, 2025

CVE-2024-12767 on NVD →

Buddyboss Platform <= 2.5.91 - Insecure Direct Object Reference to Authenticated (Subscriber+) Comment on Private Post

medium

The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the new_activity_comment AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and abo...

CVSS:
4.3
Affected:
up to 2.5.91
Fixed in:
2.6.0
Disclosed:
May 15, 2024

CVE-2024-4886 on NVD →

Buddyboss Platform <= 2.5.91 - Insecure Direct Object Reference to Authenticated (Subscriber+) Link on Private Post

medium

The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the activity_mark_fav AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 2.5.91
Fixed in:
2.6.0
Disclosed:
May 14, 2024

CVE-2024-4750 on NVD →

BuddyBoss Platform < 2.6.0 - Insecure Direct Object Reference on Like Comment

unknown
Affected:
up to 2.6.0
Fixed in:
2.6.0
Disclosed:
May 14, 2024

CVE-2024-4750 on NVD →

BuddyBoss platform < 2.7.60 - Private Comment Exposure via IDOR

unknown
Affected:
up to 2.7.60
Fixed in:
2.7.60
Disclosed:
Apr 22, 2024

CVE-2024-12767 on NVD →

Buddyboss Platform <= 1.7.8 - SQL Injection

high

The Buddyboss Platform plugin for WordPress is vulnerable to SQL Injection via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions in versions up to, and including, 1.7.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on t...

CVSS:
7.2
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Sep 16, 2021

Buddyboss Platform < 1.7.9 - Subscriber+ SQL Injection

critical
Affected:
up to 1.7.9
Fixed in:
1.7.9
Disclosed:
Sep 16, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database