plugin

Buddyboss Platform Pro Vulnerabilities

2 known security issues reported for the Buddyboss Platform Pro WordPress plugin. Most recent disclosed May 5, 2025.

2 critical

Running Buddyboss Platform Pro on your site? Check whether your installed version is affected.

Scan your site free

BuddyBoss Platform Pro <= 2.7.01 - Authentication Bypass via Apple OAuth provider

critical

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log...

CVSS:
9.8
Affected:
up to 2.7.01
Fixed in:
2.7.10
Disclosed:
May 5, 2025

CVE-2025-1909 on NVD →

BuddyBoss Platform Pro < 2.7.10 - Authentication Bypass via Apple OAuth provider

critical
Affected:
up to 2.7.10
Fixed in:
2.7.10
Disclosed:
May 5, 2025

CVE-2025-1909 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database