BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data
high
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible f...
- CVSS:
- 7.5
- Affected:
- up to 14.5.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 29, 2026
CVE-2026-1360 on NVD →
BuddyPress <= 14.4.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure
medium
The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 14.4.0. This is due to missing validation on the user_id request parameter in the messages REST endpoint, allowing non-moderator users to specify another user's ID to pass thread access checks. This m...
- CVSS:
- 4.3
- Affected:
- up to 14.4.0
- Fixed in:
- 14.5.0
- Disclosed:
- Jul 13, 2026
CVE-2026-8155 on NVD →
BuddyPress [buddypress] < 14.3.4
unknown
[en] The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attack...
- Affected:
- up to 14.3.4
- Fixed in:
- 14.3.4
- Disclosed:
- Jan 23, 2026
CVE-2024-11976 on NVD →
BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution
high
The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers t...
- CVSS:
- 7.3
- Affected:
- up to 14.3.3
- Fixed in:
- 14.3.4
- Disclosed:
- Jan 22, 2026
CVE-2024-11976 on NVD →
BuddyPress [buddypress] < 14.4.0
unknown
[en] Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.
- Affected:
- up to 14.4.0
- Fixed in:
- 14.4.0
- Disclosed:
- Oct 22, 2025
CVE-2025-62022 on NVD →
BuddyPress <= 14.3.4 - Missing Authorization
medium
The BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 14.3.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 14.3.4
- Fixed in:
- 14.4.0
- Disclosed:
- Sep 27, 2025
CVE-2025-62022 on NVD →
BuddyPress [buddypress] < 14.2.1
unknown
[en] The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enable...
- Affected:
- up to 14.2.1
- Fixed in:
- 14.2.1
- Disclosed:
- Oct 25, 2024
CVE-2024-10011 on NVD →
BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal
high
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enables fil...
- CVSS:
- 8.1
- Affected:
- up to 14.1.0
- Fixed in:
- 14.2.1
- Disclosed:
- Oct 24, 2024
CVE-2024-10011 on NVD →
BuddyPress [buddypress] < 12.5.1
unknown
[en] The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to...
- Affected:
- up to 12.5.1
- Fixed in:
- 12.5.1
- Disclosed:
- Jun 12, 2024
CVE-2024-4892 on NVD →
BuddyPress <= 12.4.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to injec...
- CVSS:
- 6.4
- Affected:
- up to 12.5.0
- Fixed in:
- 12.5.1
- Disclosed:
- Jun 11, 2024
CVE-2024-4892 on NVD →
BuddyPress [buddypress] < 12.4.1
unknown
[en] The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inj...
- Affected:
- up to 12.4.1
- Fixed in:
- 12.4.1
- Disclosed:
- May 9, 2024
CVE-2024-3974 on NVD →
BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject a...
- CVSS:
- 6.4
- Affected:
- up to 12.4.0
- Fixed in:
- 12.4.1
- Disclosed:
- May 3, 2024
CVE-2024-3974 on NVD →
BuddyPress [buddypress] < 11.3.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress: from n/a through 11.3.1.
- Affected:
- up to 11.3.2
- Fixed in:
- 11.3.2
- Disclosed:
- Dec 29, 2023
CVE-2023-50880 on NVD →
BuddyPress <= 11.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Members/Groups block properties in all versions up to, and including, 11.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above p...
- CVSS:
- 6.4
- Affected:
- up to 11.3.1
- Fixed in:
- 11.3.2
- Disclosed:
- Dec 26, 2023
CVE-2023-50880 on NVD →
BuddyPress <= 9.0.0 - SQL Injection
critical
The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get_order_by_sql()' and 'BP_Invitation::get_order_by_sql()’ parameters in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- CVSS:
- 9.8
- Affected:
- up to 9.0.0
- Fixed in:
- 9.1.1
- Disclosed:
- Aug 18, 2021
BuddyPress <= 9.0.0 - Information Disclosure via REST API
high
The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and including 9.0.0. This is due to the plugin disclosing the activation key from responses of the create_item method in the BP REST API Signup controller. This makes it possible for non-privileged attackers to o...
- CVSS:
- 8.8
- Affected:
- up to 9.0.0
- Fixed in:
- 9.1.1
- Disclosed:
- Aug 18, 2021
BuddyPress [buddypress] < 9.1.1
unknown
The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get_order_by_sql()' and 'BP_Invitation::get_order_by_sql()’ parameters in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- Affected:
- up to 9.1.1
- Fixed in:
- 9.1.1
- Disclosed:
- Aug 18, 2021
BuddyPress [buddypress] < 9.1.1
unknown
The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and including 9.0.0. This is due to the plugin disclosing the activation key from responses of the create_item method in the BP REST API Signup controller. This makes it possible for non-privileged attackers to o...
- Affected:
- up to 9.1.1
- Fixed in:
- 9.1.1
- Disclosed:
- Aug 18, 2021
BuddyPress <= 7.2.1 - Insufficient Privilege De-escalation
high
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_user_delete_or_update( ) function from versions starting at 7.0.0 to 7.2.1. This makes it possible for recently demoted user to modify groups in which they were the original creator.
- CVSS:
- 8.8
- Affected:
- up to 7.2.1
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress <= 7.2.1 - Missing Authorization to Unauthorized Group Access
medium
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group REST-API Endpoint. This makes it possible for authenticated attackers to join or request to join groups they are previously banned from.
- CVSS:
- 5.4
- Affected:
- up to 7.2.1
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress <= 7.2.1 - Missing Authorization to Group Creation
medium
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group membership REST-API Endpoint. This makes it possible for authenticated attackers to create new groups on behalf of another user.
- CVSS:
- 5.4
- Affected:
- up to 7.2.1
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress <= 7.2.1 - Missing Authorization to Private Post Activity
medium
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the activity REST-API Endpoint. This makes it possible for authenticated attackers to favorite private and hidden activity they are not authorized to acce...
- CVSS:
- 5.4
- Affected:
- up to 7.2.1
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress [buddypress] < 7.3.0
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group REST-API Endpoint. This makes it possible for authenticated attackers to join or request to join groups they are previously banned from.
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress [buddypress] < 7.3.0
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the activity REST-API Endpoint. This makes it possible for authenticated attackers to favorite private and hidden activity they are not authorized to acce...
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress [buddypress] < 7.3.0
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_user_delete_or_update( ) function from versions starting at 7.0.0 to 7.2.1. This makes it possible for recently demoted user to modify groups in which they were the original creator.
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress [buddypress] < 7.3.0
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group membership REST-API Endpoint. This makes it possible for authenticated attackers to create new groups on behalf of another user.
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
- Disclosed:
- Apr 14, 2021
BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0
unknown
[en] BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. E...
- Affected:
- 5.0.0 – 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Mar 26, 2021
CVE-2021-21389 on NVD →
BuddyPress <= 7.2.0 - Authorization Bypass to Friend Invite
medium
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddypress/v1/groups/invites REST-API endpoint in versions up to, and including, 7.2.0. This makes it possible for a member to invite another member to join a group without being friends when that group re...
- CVSS:
- 5.4
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 17, 2021
BuddyPress [buddypress] < 7.2.1
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddypress/v1/groups/invites REST-API endpoint in versions up to, and including, 7.2.0. This makes it possible for a member to invite another member to join a group without being friends when that group re...
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 17, 2021
BuddyPress 5.0.0-7.2.0 - Privilege Escalation via REST API
high
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existi...
- CVSS:
- 8.8
- Affected:
- 5.0.0 – 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 16, 2021
CVE-2021-21389 on NVD →
BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation
medium
The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.
- CVSS:
- 4.6
- Affected:
- 7.0.0 – 7.2.1
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 16, 2021
BuddyPress [buddypress] >= 7.0.0 - <= 7.2.0
unknown
The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.
- Affected:
- 7.0.0 – 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Mar 16, 2021
BuddyPress <= 7.2.0 - Authorization Bypass to Private Message Disclosure
medium
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the BuddyPress Nouveau and the BuddyPress REST API /buddypress/v1/messages endpoint in versions 5.0.0 - 7.2.0. This makes it possible for non-privileged attackers to read private messages in a thread they were...
- CVSS:
- 6.5
- Affected:
- up to 7.2.0
- Fixed in:
- 7.2.1
- Disclosed:
- Mar 7, 2021
BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0
unknown
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the BuddyPress Nouveau and the BuddyPress REST API /buddypress/v1/messages endpoint in versions 5.0.0 - 7.2.0. This makes it possible for non-privileged attackers to read private messages in a thread they were...
- Affected:
- 5.0.0 – 7.2.0
- Fixed in:
- 7.2.0
- Disclosed:
- Mar 7, 2021
BuddyPress [buddypress] < 6.4.0
unknown
Excessive user capabilities in possible rich text fields vulnerability found in WordPress BuddyPress plugin (versions <= 6.3.0).
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 29, 2020
BuddyPress <= 6.3.0 - Insufficient Input Validation
medium
The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3.0. This is due to missing authorization checks and proper sanitization on a users profile page. This makes it possible for authenticated attackers to add style attributes to the "span" and "p" elemen...
- CVSS:
- 6.4
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 27, 2020
BuddyPress [buddypress] < 6.4.0
unknown
The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3.0. This is due to missing authorization checks and proper sanitization on a users profile page. This makes it possible for authenticated attackers to add style attributes to the "span" and "p" elemen...
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
- Disclosed:
- Nov 27, 2020
BuddyPress [buddypress] < 5.1.2
unknown
[en] In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.2
- Disclosed:
- Feb 24, 2020
CVE-2020-5244 on NVD →
BuddyPress <= 5.1.1 - Sensitive Information Disclosure
high
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
- CVSS:
- 7.5
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Jan 2, 2020
CVE-2020-5244 on NVD →
BuddyPress <= 5.1.0 - Denial of Service
medium
The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.
- CVSS:
- 5.4
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Dec 23, 2019
BuddyPress [buddypress] < 5.1.1
unknown
The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Dec 23, 2019
BuddyPress [buddypress] < 1.9.2
unknown
[en] The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Apr 10, 2018
CVE-2014-1889 on NVD →
BuddyPress 2.0 - 2.7.3 - Unauthenticated Arbitrary File Deletion
critical
The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauthenticated attackers to delete the contents of arbitrary files on the server, which can lead to site takeover
- CVSS:
- 10
- Affected:
- 2.0 – 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- Dec 23, 2016
BuddyPress [buddypress] < 2.7.4
unknown
This plugin is prone to an arbitrary file deletion vulnerability.
Update the plugin.
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Dec 23, 2016
BuddyPress [buddypress] < 2.7.4
unknown
The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 - 2.7.3. This allows unauthenticated attackers to delete the contents of arbitrary files on the server, which can lead to site takeover
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.4
- Disclosed:
- Dec 23, 2016
BuddyPress [buddypress] < 2.3.5
unknown
This plugin is prone to authenticated privilege escalation vulnerability.
Update the plugin.
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Nov 12, 2015
BuddyPress <= 2.3.4 - Privilege Escalation
high
The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This makes it possible for authenticated attackers to execute otherwise privilege restricted actions and bypass capability checks.
- CVSS:
- 8.8
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.5
- Disclosed:
- Nov 11, 2015
BuddyPress [buddypress] < 2.3.5
unknown
The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This makes it possible for authenticated attackers to execute otherwise privilege restricted actions and bypass capability checks.
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
- Disclosed:
- Nov 11, 2015
BuddyPress [buddypress] < 1.7.2
unknown
This plugin is prone to multiple SQL injections.
Update the plugin.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- May 15, 2015
BuddyPress [buddypress] < 1.2.10
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.10
- Disclosed:
- May 15, 2015
BuddyPress <= 1.9.1 - Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.
- CVSS:
- 6.4
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 1, 2014
CVE-2014-1888 on NVD →
BuddyPress [buddypress] < 1.9.2
unknown
[en] Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging CVE-2014-1889.
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Feb 28, 2014
CVE-2014-1888 on NVD →
BuddyPress <= 1.9.1 - Authorization Bypass
medium
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. An attacker could exploit this vulnerability to modify the name, description, avatar and settings of groups.
- CVSS:
- 6.5
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Feb 5, 2014
CVE-2014-1889 on NVD →
BuddyPress [buddypress] < 1.5.5
unknown
[en] SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.5
- Disclosed:
- Sep 4, 2012
CVE-2012-2109 on NVD →
BuddyPress - 1.5-1.5.4 - SQL Injection
critical
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.
- CVSS:
- 9.8
- Affected:
- 1.5 – 1.5.4
- Fixed in:
- 1.5.5
- Disclosed:
- Mar 27, 2012
CVE-2012-2109 on NVD →
BuddyPress [buddypress] <= 1.2.10
unknown
BuddyPress plugin is prone to an HTML-injection vulnerability because of failure to sufficiently clean up user-supplied input. It allows an attacker to execute arbitrary script code in the browser in the context of the affected websites. In this way an attacker can steal cookie-based authentication credentials or contr...
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.10
- Disclosed:
- Sep 26, 2011
BuddyPress [buddypress] < 7.2.1
unknown
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
BuddyPress [buddypress] < 9.1.1
unknown
The plugin disclosed the activation key from responses of the create_item method in the BP REST API Signup controller.
- Affected:
- up to 9.1.1
- Fixed in:
- 9.1.1
BuddyPress [buddypress] < 9.1.1
unknown
The plugin was affected by SQL Injections via the BP_Notifications_Notification::get_order_by_sql() and BP_Invitation::get_order_by_sql() functions
- Affected:
- up to 9.1.1
- Fixed in:
- 9.1.1
BuddyPress [buddypress] < 7.3.0
unknown
- Affected:
- up to 7.3.0
- Fixed in:
- 7.3.0
BuddyPress [buddypress] < 7.2.1
unknown
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
BuddyPress [buddypress] < 2.3.5
unknown
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.5
BuddyPress [buddypress] < 7.2.1
unknown
The BuddyPress WordPress plugin, versions before 7.2.1, fixed a vulnerability that could allow a user that has just been demoted from an Administrator role to a Subscriber to add/edit/delete BuddyPress Member Types from the Administration screens introduced in the 7.0.0 release.
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
BuddyPress [buddypress] < 7.2.1
unknown
- Affected:
- up to 7.2.1
- Fixed in:
- 7.2.1
BuddyPress [buddypress] < 6.4.0
unknown
The 6.4.0 release addresses one security issue: non-capable users could add a style attributes to "span" and "p" elements in possible rich text fields of their profile page. The vulnerability has been fixed.
- Affected:
- up to 6.4.0
- Fixed in:
- 6.4.0
BuddyPress [buddypress] >= 5.0.0 - <= 5.1.1
unknown
Certain REST API requests could result in the exposure of private data.
- Affected:
- 5.0.0 – 5.1.1
- Fixed in:
- 5.1.1
BuddyPress [buddypress] < 5.1.1
unknown
A denied of service was fixed that could allow a logged in user to remove another user’s avatar and also any empty folder.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
BuddyPress [buddypress] >= 2.0 - <= 2.7.3
unknown
The BuddyPress WordPress plugin was affected by an Arbitrary File Deletion security vulnerability.
- Affected:
- 2.0 – 2.7.3
- Fixed in:
- 2.7.3
BuddyPress [buddypress] < 1.7.2
unknown
The BuddyPress WordPress plugin was affected by a Multiple SQL Injections security vulnerability.
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
BuddyPress [buddypress] < 1.2.10
unknown
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.10