BuddyPress Activity Plus <= 1.5 - Cross-Site Request Forgery
highThe buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
- CVSS:
- 8.8
- Affected:
- up to 1.5
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 14, 2015