plugin

Buying Buddy Idx Crm Vulnerabilities

4 known security issues reported for the Buying Buddy Idx Crm WordPress plugin. Most recent disclosed Jun 20, 2025.

1 high 1 medium

Running Buying Buddy Idx Crm on your site? Check whether your installed version is affected.

Scan your site free

Buying Buddy IDX CRM &#8211; Real Estate MLS Plugin [buying-buddy-idx-crm] <= 2.3.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buying Buddy Buying Buddy IDX CRM allows DOM-Based XSS. This issue affects Buying Buddy IDX CRM: from n/a through 2.3.0.

Affected:
up to 2.3.0
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-50037 on NVD →

Buying Buddy IDX CRM <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Buying Buddy IDX CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jun 19, 2025

CVE-2025-50037 on NVD →

Buying Buddy IDX CRM &#8211; Real Estate MLS Plugin [buying-buddy-idx-crm] < 2.2.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM allows Object Injection.This issue affects Buying Buddy IDX CRM: from n/a through 1.1.12.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Nov 20, 2024

CVE-2024-52446 on NVD →

Buying Buddy IDX CRM <= 1.2.8 - Cross-Site Request Forgery to PHP Object Injection

high

The Buying Buddy IDX CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to inject an object and execute magic methods in cases whe...

CVSS:
8.8
Affected:
up to 1.2.8
Fixed in:
2.2.0
Disclosed:
Nov 18, 2024

CVE-2024-52446 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database