plugin

Friends Vulnerabilities

3 known security issues reported for the Friends WordPress plugin. Most recent disclosed Jul 11, 2025.

1 high 2 medium

Running Friends on your site? Check whether your installed version is affected.

Scan your site free

Friends 3.5.1 - Authenticated (Subscriber+) PHP Object Injection

high

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable s...

CVSS:
7.5
Affected:
3.5.1 – 3.5.1
Fixed in:
3.5.2
Disclosed:
Jul 11, 2025

CVE-2025-7504 on NVD →

Friends <= 3.2.1 - Missing Authorization

medium

The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend reques...

CVSS:
5.3
Affected:
up to 3.2.1
Fixed in:
3.2.2
Disclosed:
Dec 5, 2024

CVE-2024-12028 on NVD →

Friends <= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request Forgery

medium

The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from...

CVSS:
5.5
Affected:
up to 2.8.5
Fixed in:
2.8.6
Disclosed:
Feb 28, 2024

CVE-2024-1978 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database