VYPR
High severityNVD Advisory· Published Feb 24, 2020· Updated Aug 4, 2024

Private data exposure via REST API in BuddyPress

CVE-2020-5244

Description

In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
buddypress/buddypressPackagist
< 5.1.25.1.2

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.