plugin

Buddypress Vulnerabilities

70 known security issues reported for the Buddypress WordPress plugin. Most recent disclosed Jul 29, 2026.

3 critical 8 high 15 medium

Running Buddypress on your site? Check whether your installed version is affected.

Scan your site free

BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data

high

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible f...

CVSS:
7.5
Affected:
up to 14.5.0
Fix:
No patched version reported
Disclosed:
Jul 29, 2026

CVE-2026-1360 on NVD →

BuddyPress <= 14.4.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure

medium

The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 14.4.0. This is due to missing validation on the user_id request parameter in the messages REST endpoint, allowing non-moderator users to specify another user's ID to pass thread access checks. This m...

CVSS:
4.3
Affected:
up to 14.4.0
Fixed in:
14.5.0
Disclosed:
Jul 13, 2026

CVE-2026-8155 on NVD →

BuddyPress [buddypress] < 14.3.4

unknown

[en] The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attack...

Affected:
up to 14.3.4
Fixed in:
14.3.4
Disclosed:
Jan 23, 2026

CVE-2024-11976 on NVD →

BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution

high

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers t...

CVSS:
7.3
Affected:
up to 14.3.3
Fixed in:
14.3.4
Disclosed:
Jan 22, 2026

CVE-2024-11976 on NVD →

BuddyPress [buddypress] < 14.4.0

unknown

[en] Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.

Affected:
up to 14.4.0
Fixed in:
14.4.0
Disclosed:
Oct 22, 2025

CVE-2025-62022 on NVD →

BuddyPress <= 14.3.4 - Missing Authorization

medium

The BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 14.3.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 14.3.4
Fixed in:
14.4.0
Disclosed:
Sep 27, 2025

CVE-2025-62022 on NVD →

BuddyPress [buddypress] < 14.2.1

unknown

[en] The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enable...

Affected:
up to 14.2.1
Fixed in:
14.2.1
Disclosed:
Oct 25, 2024

CVE-2024-10011 on NVD →

BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal

high

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enables fil...

CVSS:
8.1
Affected:
up to 14.1.0
Fixed in:
14.2.1
Disclosed:
Oct 24, 2024

CVE-2024-10011 on NVD →

BuddyPress [buddypress] < 12.5.1

unknown

[en] The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to...

Affected:
up to 12.5.1
Fixed in:
12.5.1
Disclosed:
Jun 12, 2024

CVE-2024-4892 on NVD →

BuddyPress <= 12.4.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to injec...

CVSS:
6.4
Affected:
up to 12.5.0
Fixed in:
12.5.1
Disclosed:
Jun 11, 2024

CVE-2024-4892 on NVD →

BuddyPress [buddypress] < 12.4.1

unknown

[en] The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inj...

Affected:
up to 12.4.1
Fixed in:
12.4.1
Disclosed:
May 9, 2024

CVE-2024-3974 on NVD →

BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject a...

CVSS:
6.4
Affected:
up to 12.4.0
Fixed in:
12.4.1
Disclosed:
May 3, 2024

CVE-2024-3974 on NVD →

BuddyPress [buddypress] < 11.3.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress: from n/a through 11.3.1.

Affected:
up to 11.3.2
Fixed in:
11.3.2
Disclosed:
Dec 29, 2023

CVE-2023-50880 on NVD →

BuddyPress <= 11.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Members/Groups block properties in all versions up to, and including, 11.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above p...

CVSS:
6.4
Affected:
up to 11.3.1
Fixed in:
11.3.2
Disclosed:
Dec 26, 2023

CVE-2023-50880 on NVD →

BuddyPress <= 9.0.0 - SQL Injection

critical

The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get_order_by_sql()' and 'BP_Invitation::get_order_by_sql()’ parameters in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

CVSS:
9.8
Affected:
up to 9.0.0
Fixed in:
9.1.1
Disclosed:
Aug 18, 2021

BuddyPress <= 9.0.0 - Information Disclosure via REST API

high

The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and including 9.0.0. This is due to the plugin disclosing the activation key from responses of the create_item method in the BP REST API Signup controller. This makes it possible for non-privileged attackers to o...

CVSS:
8.8
Affected:
up to 9.0.0
Fixed in:
9.1.1
Disclosed:
Aug 18, 2021

BuddyPress [buddypress] < 9.1.1

unknown

The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get_order_by_sql()' and 'BP_Invitation::get_order_by_sql()’ parameters in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Affected:
up to 9.1.1
Fixed in:
9.1.1
Disclosed:
Aug 18, 2021

BuddyPress [buddypress] < 9.1.1

unknown

The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and including 9.0.0. This is due to the plugin disclosing the activation key from responses of the create_item method in the BP REST API Signup controller. This makes it possible for non-privileged attackers to o...

Affected:
up to 9.1.1
Fixed in:
9.1.1
Disclosed:
Aug 18, 2021

BuddyPress <= 7.2.1 - Insufficient Privilege De-escalation

high

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_user_delete_or_update( ) function from versions starting at 7.0.0 to 7.2.1. This makes it possible for recently demoted user to modify groups in which they were the original creator.

CVSS:
8.8
Affected:
up to 7.2.1
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress <= 7.2.1 - Missing Authorization to Unauthorized Group Access

medium

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group REST-API Endpoint. This makes it possible for authenticated attackers to join or request to join groups they are previously banned from.

CVSS:
5.4
Affected:
up to 7.2.1
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress <= 7.2.1 - Missing Authorization to Group Creation

medium

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group membership REST-API Endpoint. This makes it possible for authenticated attackers to create new groups on behalf of another user.

CVSS:
5.4
Affected:
up to 7.2.1
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress <= 7.2.1 - Missing Authorization to Private Post Activity

medium

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the activity REST-API Endpoint. This makes it possible for authenticated attackers to favorite private and hidden activity they are not authorized to acce...

CVSS:
5.4
Affected:
up to 7.2.1
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress [buddypress] < 7.3.0

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group REST-API Endpoint. This makes it possible for authenticated attackers to join or request to join groups they are previously banned from.

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress [buddypress] < 7.3.0

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the activity REST-API Endpoint. This makes it possible for authenticated attackers to favorite private and hidden activity they are not authorized to acce...

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress [buddypress] < 7.3.0

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_user_delete_or_update( ) function from versions starting at 7.0.0 to 7.2.1. This makes it possible for recently demoted user to modify groups in which they were the original creator.

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress [buddypress] < 7.3.0

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group membership REST-API Endpoint. This makes it possible for authenticated attackers to create new groups on behalf of another user.

Affected:
up to 7.3.0
Fixed in:
7.3.0
Disclosed:
Apr 14, 2021

BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0

unknown

[en] BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. E...

Affected:
5.0.0 – 7.2.0
Fixed in:
7.2.0
Disclosed:
Mar 26, 2021

CVE-2021-21389 on NVD →

BuddyPress <= 7.2.0 - Authorization Bypass to Friend Invite

medium

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddypress/v1/groups/invites REST-API endpoint in versions up to, and including, 7.2.0. This makes it possible for a member to invite another member to join a group without being friends when that group re...

CVSS:
5.4
Affected:
up to 7.2.0
Fixed in:
7.2.1
Disclosed:
Mar 17, 2021

BuddyPress [buddypress] < 7.2.1

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddypress/v1/groups/invites REST-API endpoint in versions up to, and including, 7.2.0. This makes it possible for a member to invite another member to join a group without being friends when that group re...

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Mar 17, 2021

BuddyPress 5.0.0-7.2.0 - Privilege Escalation via REST API

high

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existi...

CVSS:
8.8
Affected:
5.0.0 – 7.2.0
Fixed in:
7.2.1
Disclosed:
Mar 16, 2021

CVE-2021-21389 on NVD →

BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation

medium

The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.

CVSS:
4.6
Affected:
7.0.0 – 7.2.1
Fixed in:
7.2.1
Disclosed:
Mar 16, 2021

BuddyPress [buddypress] >= 7.0.0 - <= 7.2.0

unknown

The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.

Affected:
7.0.0 – 7.2.0
Fixed in:
7.2.0
Disclosed:
Mar 16, 2021

BuddyPress <= 7.2.0 - Authorization Bypass to Private Message Disclosure

medium

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the BuddyPress Nouveau and the BuddyPress REST API /buddypress/v1/messages endpoint in versions 5.0.0 - 7.2.0. This makes it possible for non-privileged attackers to read private messages in a thread they were...

CVSS:
6.5
Affected:
up to 7.2.0
Fixed in:
7.2.1
Disclosed:
Mar 7, 2021

BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0

unknown

The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the BuddyPress Nouveau and the BuddyPress REST API /buddypress/v1/messages endpoint in versions 5.0.0 - 7.2.0. This makes it possible for non-privileged attackers to read private messages in a thread they were...

Affected:
5.0.0 – 7.2.0
Fixed in:
7.2.0
Disclosed:
Mar 7, 2021

BuddyPress [buddypress] < 6.4.0

unknown

Excessive user capabilities in possible rich text fields vulnerability found in WordPress BuddyPress plugin (versions <= 6.3.0).

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 29, 2020

BuddyPress <= 6.3.0 - Insufficient Input Validation

medium

The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3.0. This is due to missing authorization checks and proper sanitization on a users profile page. This makes it possible for authenticated attackers to add style attributes to the "span" and "p" elemen...

CVSS:
6.4
Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 27, 2020

BuddyPress [buddypress] < 6.4.0

unknown

The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3.0. This is due to missing authorization checks and proper sanitization on a users profile page. This makes it possible for authenticated attackers to add style attributes to the "span" and "p" elemen...

Affected:
up to 6.4.0
Fixed in:
6.4.0
Disclosed:
Nov 27, 2020

BuddyPress [buddypress] < 5.1.2

unknown

[en] In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

Affected:
up to 5.1.2
Fixed in:
5.1.2
Disclosed:
Feb 24, 2020

CVE-2020-5244 on NVD →

BuddyPress <= 5.1.1 - Sensitive Information Disclosure

high

In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

CVSS:
7.5
Affected:
up to 5.1.1
Fixed in:
5.1.2
Disclosed:
Jan 2, 2020

CVE-2020-5244 on NVD →

BuddyPress <= 5.1.0 - Denial of Service

medium

The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.

CVSS:
5.4
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Dec 23, 2019

BuddyPress [buddypress] < 5.1.1

unknown

The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Dec 23, 2019

BuddyPress [buddypress] < 1.9.2

unknown

[en] The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Apr 10, 2018

CVE-2014-1889 on NVD →

BuddyPress 2.0 - 2.7.3 - Unauthenticated Arbitrary File Deletion

critical

The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauthenticated attackers to delete the contents of arbitrary files on the server, which can lead to site takeover

CVSS:
10
Affected:
2.0 – 2.7.3
Fixed in:
2.7.4
Disclosed:
Dec 23, 2016

BuddyPress [buddypress] < 2.7.4

unknown

This plugin is prone to an arbitrary file deletion vulnerability. Update the plugin.

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Dec 23, 2016

BuddyPress [buddypress] < 2.7.4

unknown

The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauthenticated attackers to delete the contents of arbitrary files on the server, which can lead to site takeover

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Dec 23, 2016

BuddyPress [buddypress] < 2.3.5

unknown

This plugin is prone to authenticated privilege escalation vulnerability. Update the plugin.

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Nov 12, 2015

BuddyPress <= 2.3.4 - Privilege Escalation

high

The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This makes it possible for authenticated attackers to execute otherwise privilege restricted actions and bypass capability checks.

CVSS:
8.8
Affected:
up to 2.3.4
Fixed in:
2.3.5
Disclosed:
Nov 11, 2015

BuddyPress [buddypress] < 2.3.5

unknown

The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This makes it possible for authenticated attackers to execute otherwise privilege restricted actions and bypass capability checks.

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Nov 11, 2015

BuddyPress [buddypress] < 1.7.2

unknown

This plugin is prone to multiple SQL injections. Update the plugin.

Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
May 15, 2015

BuddyPress [buddypress] < 1.2.10

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 1.2.10
Fixed in:
1.2.10
Disclosed:
May 15, 2015

BuddyPress <= 1.9.1 - Stored Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

CVSS:
6.4
Affected:
up to 1.9.1
Fixed in:
1.9.2
Disclosed:
Aug 1, 2014

CVE-2014-1888 on NVD →

BuddyPress [buddypress] < 1.9.2

unknown

[en] Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Feb 28, 2014

CVE-2014-1888 on NVD →

BuddyPress <= 1.9.1 - Authorization Bypass

medium

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. An attacker could exploit this vulnerability to modify the name, description, avatar and settings of groups.

CVSS:
6.5
Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Feb 5, 2014

CVE-2014-1889 on NVD →

BuddyPress [buddypress] < 1.5.5

unknown

[en] SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Sep 4, 2012

CVE-2012-2109 on NVD →

BuddyPress - 1.5-1.5.4 - SQL Injection

critical

SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.

CVSS:
9.8
Affected:
1.5 – 1.5.4
Fixed in:
1.5.5
Disclosed:
Mar 27, 2012

CVE-2012-2109 on NVD →

BuddyPress [buddypress] <= 1.2.10

unknown

BuddyPress plugin is prone to an HTML-injection vulnerability because of failure to sufficiently clean up user-supplied input. It allows an attacker to execute arbitrary script code in the browser in the context of the affected websites. In this way an attacker can steal cookie-based authentication credentials or contr...

Affected:
up to 1.2.10
Fixed in:
1.2.10
Disclosed:
Sep 26, 2011

BuddyPress [buddypress] < 7.2.1

unknown
Affected:
up to 7.2.1
Fixed in:
7.2.1

BuddyPress [buddypress] < 9.1.1

unknown

The plugin disclosed the activation key from responses of the create_item method in the BP REST API Signup controller.

Affected:
up to 9.1.1
Fixed in:
9.1.1

BuddyPress [buddypress] < 9.1.1

unknown

The plugin was affected by SQL Injections via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions

Affected:
up to 9.1.1
Fixed in:
9.1.1

BuddyPress [buddypress] < 7.3.0

unknown
Affected:
up to 7.3.0
Fixed in:
7.3.0

BuddyPress [buddypress] < 7.2.1

unknown
Affected:
up to 7.2.1
Fixed in:
7.2.1

BuddyPress [buddypress] < 2.3.5

unknown
Affected:
up to 2.3.5
Fixed in:
2.3.5

BuddyPress [buddypress] < 7.2.1

unknown

The BuddyPress WordPress plugin, versions before 7.2.1, fixed a vulnerability that could allow a user that has just been demoted from an Administrator role to a Subscriber to add/edit/delete BuddyPress Member Types from the Administration screens introduced in the 7.0.0 release.

Affected:
up to 7.2.1
Fixed in:
7.2.1

BuddyPress [buddypress] < 7.2.1

unknown
Affected:
up to 7.2.1
Fixed in:
7.2.1

BuddyPress [buddypress] < 6.4.0

unknown

The 6.4.0 release addresses one security issue: non-capable users could add a style attributes to &quot;span&quot; and &quot;p&quot; elements in possible rich text fields of their profile page. The vulnerability has been fixed.

Affected:
up to 6.4.0
Fixed in:
6.4.0

BuddyPress [buddypress] >= 5.0.0 - <= 5.1.1

unknown

Certain REST API requests could result in the exposure of private data.

Affected:
5.0.0 – 5.1.1
Fixed in:
5.1.1

BuddyPress [buddypress] < 5.1.1

unknown

A denied of service was fixed that could allow a logged in user to remove another user&rsquo;s avatar and also any empty folder.

Affected:
up to 5.1.1
Fixed in:
5.1.1

BuddyPress [buddypress] >= 2.0 - <= 2.7.3

unknown

The BuddyPress WordPress plugin was affected by an Arbitrary File Deletion security vulnerability.

Affected:
2.0 – 2.7.3
Fixed in:
2.7.3

BuddyPress [buddypress] < 1.7.2

unknown

The BuddyPress WordPress plugin was affected by a Multiple SQL Injections security vulnerability.

Affected:
up to 1.7.2
Fixed in:
1.7.2

BuddyPress [buddypress] < 1.2.10

unknown
Affected:
up to 1.2.10
Fixed in:
1.2.10

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database