Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.7 - Unauthenticated PHP Object Injection
high
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7. This is due to deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a P...
- CVSS:
- 8.1
- Affected:
- up to 1.3.7
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-73397 on NVD →
Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter
medium
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Apr 17, 2026
CVE-2026-1559 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] <= 1.3.5 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.5.
- Affected:
- up to 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-69014 on NVD →
Youzify <= 1.3.7 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web reques...
- CVSS:
- 6.4
- Affected:
- up to 1.3.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 27, 2025
CVE-2025-69014 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.3.4
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.2. This makes it possible for authenticat...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Jan 25, 2025
CVE-2024-13370 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.3.3
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it p...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 25, 2025
CVE-2024-12113 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.3.5
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.2. This makes it possible for authenticated...
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jan 25, 2025
CVE-2024-13368 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.3. This makes it possible for authenticated at...
- CVSS:
- 6.5
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Jan 24, 2025
CVE-2024-13370 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4. This makes it possible for authenticated atta...
- CVSS:
- 4.3
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Jan 24, 2025
CVE-2024-13368 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it possib...
- CVSS:
- 4.3
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Jan 24, 2025
CVE-2024-12113 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.8
unknown
[en] Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Nov 1, 2024
CVE-2024-39635 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.3.1
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on use...
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 10, 2024
CVE-2024-8987 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.3.1
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for au...
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 10, 2024
CVE-2024-9067 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user sup...
- CVSS:
- 6.4
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 9, 2024
CVE-2024-8987 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for authent...
- CVSS:
- 4.3
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Oct 9, 2024
CVE-2024-9067 on NVD →
Youzify <= 1.2.6 - Missing Authorization
medium
The Youzify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.8
- Disclosed:
- Jul 24, 2024
CVE-2024-39635 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.6
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 9, 2024
CVE-2024-37494 on NVD →
Youzify <= 1.2.5 - Authenticated (Contributor+) SQL Injection
critical
The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 9.9
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 4, 2024
CVE-2024-37494 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.6
unknown
[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jun 20, 2024
CVE-2024-4742 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...
- CVSS:
- 6.5
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Jun 19, 2024
CVE-2024-4742 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.3
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Dec 21, 2023
CVE-2023-47191 on NVD →
Youzify <= 1.2.2 - Insecure Direct Object Reference
medium
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.5
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.3
- Disclosed:
- Nov 3, 2023
CVE-2023-47191 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.2
unknown
[en] The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Feb 21, 2023
CVE-2023-0059 on NVD →
Youzify <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above...
- CVSS:
- 6.4
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Jan 24, 2023
CVE-2023-0059 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.2.0
unknown
[en] The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 1, 2022
CVE-2022-1950 on NVD →
Youzify <= 1.1.9 - SQL Injection
critical
The Youzify Plugin for WordPress is vulnerable to SQL injection via the 'youzify_media_pagination' AJAX action in versions before 1.2.0 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...
- CVSS:
- 9.8
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 13, 2022
CVE-2022-1950 on NVD →
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress [youzify] < 1.0.7
unknown
[en] The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profil...
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Aug 2, 2021
CVE-2021-24443 on NVD →
Youzify <= 1.0.6 - Stored Cross-Site Scripting
medium
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. Th...
- CVSS:
- 6.4
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Jun 28, 2021
CVE-2021-24443 on NVD →