WordPress BuddyPress before version 7.2.1 is susceptible to a privilege escalation vulnerability that can be leveraged to perform remote code execution.
id: CVE-2021-21389
info:
name: BuddyPress REST API <7.2.1 - Privilege Escalation/Remote Code Exe
...