CVE-2024-11976
BuddyPress
Minimum safe version
14.4.0
Update to 14.4.0 or later to address 38 fixable vulnerabilities
CVE-2025-62022
CVE-2024-10011
CVE-2024-4892
CVE-2024-3974
WordPress BuddyPress Plugin <= 11.3.1 is vulnerable to Cross Site Scripting (XSS)
BuddyPress <= 2.3.4 - Privilege Escalation
BuddyPress 2.0 - 2.7.3 - Unauthenticated Arbitrary File Deletion
BuddyPress <= 5.1.0 - Denial of Service
CVE-2020-5244
BuddyPress <= 6.3.0 - Insufficient Input Validation
BuddyPress <= 7.2.0 - Authorization Bypass to Private Message Disclosure
BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation
BuddyPress <= 7.2.0 - Authorization Bypass to Friend Invite
BuddyPress <= 7.2.1 - Missing Authorization to Unauthorized Group Access
BuddyPress <= 7.2.1 - Missing Authorization to Private Post Activity
BuddyPress <= 7.2.1 - Insufficient Privilege De-escalation
BuddyPress <= 7.2.1 - Missing Authorization to Group Creation
BuddyPress <= 9.0.0 - Information Disclosure via REST API
BuddyPress <= 9.0.0 - SQL Injection
BuddyPress 1.7.1 - Multiple SQL Injections
wpscan.com
wpscan.com
BuddyPress 2.0-2.7.3 - Arbitrary File Deletion
BuddyPress < 5.1.1 - Denial of Service
BuddyPress 5.0.0-5.1.1 - Private Data Exposure via REST API
BuddyPress < 6.4.0 - Lack of Capability Check on Profile Page
wpscan.com
BuddyPress < 7.2.1 - Manage BuddyPress Member Types
wpscan.com
wpscan.com
wpscan.com
BuddyPress < 9.1.1 - SQL Injections
BuddyPress < 9.1.1 - Activation Key Disclosure
WordPress BuddyPress Plugin 1.2.10 - HTML Injection Vulnerability
WordPress BuddyPress Plugin <= 1.2.9 - SQL Injection
WordPress BuddyPress Plugin <= 1.7.1 - Multiple SQL Injections
WordPress BuddyPress Plugin <= 2.3.4 - Privilege Escalation
WordPress BuddyPress Plugin <= 2.7.3 - Arbitrary File Deletion
WordPress BuddyPress plugin <= 6.3.0 - Excessive user capabilities in possible rich text fields vulnerability
CVE-2012-2109
BuddyPress <= 1.9.1 - Stored Cross-Site Scripting
CVE-2014-1889
CVE-2021-21389