plugin

Youzify Vulnerabilities

28 known security issues reported for the Youzify WordPress plugin. Most recent disclosed Aug 18, 2026.

2 critical 1 high 12 medium

Running Youzify on your site? Check whether your installed version is affected.

Scan your site free

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.7 - Unauthenticated PHP Object Injection

high

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7. This is due to deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a P...

CVSS:
8.1
Affected:
up to 1.3.7
Fix:
No patched version reported
Disclosed:
Aug 18, 2026

CVE-2026-73397 on NVD →

Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter

medium

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject...

CVSS:
6.4
Affected:
up to 1.3.6
Fixed in:
1.3.7
Disclosed:
Apr 17, 2026

CVE-2026-1559 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] <= 1.3.5 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.5.

Affected:
up to 1.3.5
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-69014 on NVD →

Youzify <= 1.3.7 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web reques...

CVSS:
6.4
Affected:
up to 1.3.7
Fix:
No patched version reported
Disclosed:
Dec 27, 2025

CVE-2025-69014 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.3.4

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.2. This makes it possible for authenticat...

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Jan 25, 2025

CVE-2024-13370 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.3.3

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it p...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jan 25, 2025

CVE-2024-12113 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.3.5

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.2. This makes it possible for authenticated...

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jan 25, 2025

CVE-2024-13368 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.3. This makes it possible for authenticated at...

CVSS:
6.5
Affected:
up to 1.3.3
Fixed in:
1.3.4
Disclosed:
Jan 24, 2025

CVE-2024-13370 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4. This makes it possible for authenticated atta...

CVSS:
4.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Jan 24, 2025

CVE-2024-13368 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it possib...

CVSS:
4.3
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Jan 24, 2025

CVE-2024-12113 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.8

unknown

[en] Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Nov 1, 2024

CVE-2024-39635 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.3.1

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on use...

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 10, 2024

CVE-2024-8987 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.3.1

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for au...

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Oct 10, 2024

CVE-2024-9067 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user sup...

CVSS:
6.4
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Oct 9, 2024

CVE-2024-8987 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for authent...

CVSS:
4.3
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Oct 9, 2024

CVE-2024-9067 on NVD →

Youzify <= 1.2.6 - Missing Authorization

medium

The Youzify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.2.6
Fixed in:
1.2.8
Disclosed:
Jul 24, 2024

CVE-2024-39635 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.6

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 9, 2024

CVE-2024-37494 on NVD →

Youzify <= 1.2.5 - Authenticated (Contributor+) SQL Injection

critical

The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
9.9
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jul 4, 2024

CVE-2024-37494 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.6

unknown

[en] The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jun 20, 2024

CVE-2024-4742 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

CVSS:
6.5
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Jun 19, 2024

CVE-2024-4742 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.3

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.

Affected:
up to 1.2.3
Fixed in:
1.2.3
Disclosed:
Dec 21, 2023

CVE-2023-47191 on NVD →

Youzify <= 1.2.2 - Insecure Direct Object Reference

medium

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, wi...

CVSS:
6.5
Affected:
up to 1.2.2
Fixed in:
1.2.3
Disclosed:
Nov 3, 2023

CVE-2023-47191 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.2

unknown

[en] The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Feb 21, 2023

CVE-2023-0059 on NVD →

Youzify <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jan 24, 2023

CVE-2023-0059 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.2.0

unknown

[en] The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Aug 1, 2022

CVE-2022-1950 on NVD →

Youzify <= 1.1.9 - SQL Injection

critical

The Youzify Plugin for WordPress is vulnerable to SQL injection via the 'youzify_media_pagination' AJAX action in versions before 1.2.0 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append ad...

CVSS:
9.8
Affected:
up to 1.1.9
Fixed in:
1.2.0
Disclosed:
Jul 13, 2022

CVE-2022-1950 on NVD →

Youzify – BuddyPress Community, User Profile, Social Network &amp; Membership Plugin for WordPress [youzify] < 1.0.7

unknown

[en] The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profil...

Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Aug 2, 2021

CVE-2021-24443 on NVD →

Youzify <= 1.0.6 - Stored Cross-Site Scripting

medium

The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. Th...

CVSS:
6.4
Affected:
up to 1.0.6
Fixed in:
1.0.7
Disclosed:
Jun 28, 2021

CVE-2021-24443 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database