VYPR

Buddypress

by WordPress

Source repositories

CVEs (14)

  • CVE-2026-5144HigApr 11, 2026
    risk 0.50cvss 8.8epss 0.00

    The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user…

  • CVE-2025-62022HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.

  • CVE-2024-11976HigJan 23, 2026
    risk 0.47cvss 7.3epss 0.00

    The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2026-53673HigJun 10, 2026
    risk 0.46cvss 8.1epss 0.00

    BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to…

  • CVE-2024-10011HigOct 25, 2024
    risk 0.46cvss 8.1epss 0.01

    The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the…

  • CVE-2020-37233MedMay 16, 2026
    risk 0.42cvss 6.4epss 0.00

    WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with…

  • CVE-2023-50880MedDec 29, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The BuddyPress Community BuddyPress allows Stored XSS.This issue affects BuddyPress: from n/a through 11.3.1.

  • CVE-2026-53674HigJun 10, 2026
    risk 0.39cvss 7.1epss 0.00

    BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters.…

  • CVE-2014-1889MedApr 10, 2018
    risk 0.39cvss 6.5epss 0.11

    The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.

  • CVE-2024-4892MedJun 12, 2024
    risk 0.35cvss 6.4epss 0.00

    The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2025-3793MedApr 24, 2025
    risk 0.27cvss 4.2epss 0.00

    The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and…

  • CVE-2026-53675MedJun 10, 2026
    risk 0.21cvss 4.3epss 0.00

    BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the…

  • CVE-2014-1888Mar 1, 2014
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by…

  • CVE-2012-2109Sep 4, 2012
    risk 0.00cvss epss 0.03

    SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.