Friends 3.5.1 - Authenticated (Subscriber+) PHP Object Injection
high
The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable s...
- CVSS:
- 7.5
- Affected:
- 3.5.1 – 3.5.1
- Fixed in:
- 3.5.2
- Disclosed:
- Jul 11, 2025
CVE-2025-7504 on NVD →
Friends <= 3.2.1 - Missing Authorization
medium
The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to send arbitrary friend requests on behalf of another website, accept the friend reques...
- CVSS:
- 5.3
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.2
- Disclosed:
- Dec 5, 2024
CVE-2024-12028 on NVD →
Friends <= 2.8.5 - Authenticated (Admin+) Blind Server-Side Request Forgery
medium
The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.5 via the discover_available_feeds function. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from...
- CVSS:
- 5.5
- Affected:
- up to 2.8.5
- Fixed in:
- 2.8.6
- Disclosed:
- Feb 28, 2024
CVE-2024-1978 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database