Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

buddypress — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting buddypress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BuddyPress is an open-source social networking platform that enables WordPress websites to create community features like user profiles, activity streams, and groups. Historically, it has been vulnerable to common web application security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, often stemming from insufficient input validation and improper access controls. While no major public security incidents have been widely reported, the 7 CVEs on record highlight ongoing security concerns that require regular updates and careful configuration. Its plugin architecture and extensive customization options introduce potential attack surfaces that administrators must actively monitor and secure.

Top products by buddypress: BuddyPress
CVE ID Title CVSS Severity Published
CVE-2024-12145 BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion — BuddyPress CWE-862 4.3 Medium 2026-09-11
CVE-2026-1360 BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data — BuddyPress CWE-502 7.5 High 2026-07-30
CVE-2026-53675 BuddyPress 14.4.0 Friends List IDOR via REST API — BuddyPress CWE-639 4.3 Medium 2026-06-09
CVE-2026-53673 BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter — BuddyPress CWE-639 8.1 High 2026-06-09
CVE-2026-53674 BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution — BuddyPress CWE-943 7.1 High 2026-06-09
CVE-2024-11976 BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution — BuddyPress CWE-94 7.3 High 2026-01-23
CVE-2025-62022 WordPress BuddyPress plugin <= 14.3.4 - Broken Access Control vulnerability — BuddyPress CWE-862 7.5 High 2025-10-22
CVE-2024-10011 BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal — BuddyPress CWE-22 8.1 High 2024-10-25
CVE-2024-4892 BuddyPress <= 12.4.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting — BuddyPress CWE-79 6.4 Medium 2024-06-12
CVE-2024-3974 BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting — BuddyPress CWE-79 6.4 Medium 2024-05-09
CVE-2021-21389 BuddyPress privilege escalation via REST API — BuddyPress CWE-863 8.1 High 2021-03-26
CVE-2020-5244 Private data exposure via REST API in BuddyPress — BuddyPress CWE-284 8.0 High 2020-02-24

This page lists every published CVE security advisory associated with buddypress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.