All 3 CVE vulnerabilities found in Activity Plus Reloaded for BuddyPress, with AI-generated Chinese analysis, references, and POCs.
Vendor: buddydev
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-62949 | WordPress Activity Plus Reloaded for BuddyPress plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability CWE-79 | 5.4AI | MediumAI | 2025-10-27 |
| CVE-2025-30957 | WordPress Activity Plus Reloaded for BuddyPress plugin <= 1.1.2 - Broken Access Control Vulnerability CWE-862 | 5.4 | Medium | 2025-06-06 |
| CVE-2024-11913 | Activity Plus Reloaded for BuddyPress <= 1.1.1 - Authenticated (Subscriber+) Blind Server-Side Request Forgery CWE-918 | 5.4 | Medium | 2025-01-24 |
All 3 known CVE vulnerabilities affecting Activity Plus Reloaded for BuddyPress with full Chinese analysis, references, and POCs where available.