BuddyBoss Platform <= 3.0.5 - Unauthenticated SQL Injection
high
The BuddyBoss Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queri...
- CVSS:
- 7.5
- Affected:
- up to 3.0.5
- Fixed in:
- 3.1.0
- Disclosed:
- Jul 9, 2026
CVE-2026-59514 on NVD →
BuddyBoss Platform <= 3.0.4 - Authenticated (Subscriber+) PHP Object Injection
high
The BuddyBoss Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulne...
- CVSS:
- 7.5
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Jun 23, 2026
CVE-2026-56032 on NVD →
BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'
medium
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 2.8.50
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13858 on NVD →
BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'
medium
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above...
- CVSS:
- 6.4
- Affected:
- up to 2.8.50
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13860 on NVD →
BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function
medium
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 6.4
- Affected:
- up to 2.8.50
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13859 on NVD →
BuddyBoss Platform < 2.8.51 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function
high
- Affected:
- up to 2.8.51
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13859 on NVD →
BuddyBoss Platform < 2.8.51 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title'
high
- Affected:
- up to 2.8.51
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13860 on NVD →
BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'
high
- Affected:
- up to 2.8.51
- Fixed in:
- 2.8.51
- Disclosed:
- May 1, 2025
CVE-2024-13858 on NVD →
BuddyBoss Platform <= 2.7.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'
medium
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 2.7.70
- Fixed in:
- 2.8.00
- Disclosed:
- Feb 26, 2025
CVE-2024-13402 on NVD →
BuddyBoss Platform < 2.8.00 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title'
high
- Affected:
- up to 2.8.00
- Fixed in:
- 2.8.00
- Disclosed:
- Feb 26, 2025
CVE-2024-13402 on NVD →
BuddyBoss Platform < 2.7.60 - Insecure Direct Object Reference to Private Post Comment Exposure
medium
The BuddyBoss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 2.7.60 (exclusive) due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view comments on private posts.
- CVSS:
- 4.3
- Affected:
- up to 2.7.60
- Fixed in:
- 2.7.60
- Disclosed:
- Jan 14, 2025
CVE-2024-12767 on NVD →
Buddyboss Platform <= 2.5.91 - Insecure Direct Object Reference to Authenticated (Subscriber+) Comment on Private Post
medium
The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the new_activity_comment AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and abo...
- CVSS:
- 4.3
- Affected:
- up to 2.5.91
- Fixed in:
- 2.6.0
- Disclosed:
- May 15, 2024
CVE-2024-4886 on NVD →
Buddyboss Platform <= 2.5.91 - Insecure Direct Object Reference to Authenticated (Subscriber+) Link on Private Post
medium
The Buddyboss Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.5.91 via the activity_mark_fav AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 2.5.91
- Fixed in:
- 2.6.0
- Disclosed:
- May 14, 2024
CVE-2024-4750 on NVD →
BuddyBoss Platform < 2.6.0 - Insecure Direct Object Reference on Like Comment
unknown
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.0
- Disclosed:
- May 14, 2024
CVE-2024-4750 on NVD →
BuddyBoss platform < 2.7.60 - Private Comment Exposure via IDOR
unknown
- Affected:
- up to 2.7.60
- Fixed in:
- 2.7.60
- Disclosed:
- Apr 22, 2024
CVE-2024-12767 on NVD →
Buddyboss Platform <= 1.7.8 - SQL Injection
high
The Buddyboss Platform plugin for WordPress is vulnerable to SQL Injection via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions in versions up to, and including, 1.7.8 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on t...
- CVSS:
- 7.2
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.9
- Disclosed:
- Sep 16, 2021
Buddyboss Platform < 1.7.9 - Subscriber+ SQL Injection
critical
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Sep 16, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database