BuddyPress

Vulnerabilities 44Slug buddypressLatest version 14.4.0WordPress.org →

Minimum safe version

14.4.0

Update to 14.4.0 or later to address 38 fixable vulnerabilities

Latest available14.4.0 Affected up to7.2.0
Medium 6.5
2024-12-26< 11.3.2

WordPress BuddyPress Plugin <= 11.3.1 is vulnerable to Cross Site Scripting (XSS)

N/A
2015-11-11< 2.3.5

BuddyPress <= 2.3.4 - Privilege Escalation

N/A
2016-12-23< 2.7.4

BuddyPress 2.0 - 2.7.3 - Unauthenticated Arbitrary File Deletion

N/A
2019-12-23< 5.1.1

BuddyPress <= 5.1.0 - Denial of Service

N/A
2020-11-27< 6.4.0

BuddyPress <= 6.3.0 - Insufficient Input Validation

N/A
2021-03-07≥ 5.0.0 and ≤ 7.2.0

BuddyPress <= 7.2.0 - Authorization Bypass to Private Message Disclosure

N/A
2021-03-16≥ 7.0.0 and ≤ 7.2.0

BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation

N/A
2021-03-17< 7.2.1

BuddyPress <= 7.2.0 - Authorization Bypass to Friend Invite

N/A
2021-04-14< 7.3.0

BuddyPress <= 7.2.1 - Missing Authorization to Unauthorized Group Access

N/A
2021-04-14< 7.3.0

BuddyPress <= 7.2.1 - Missing Authorization to Private Post Activity

N/A
2021-04-14< 7.3.0

BuddyPress <= 7.2.1 - Insufficient Privilege De-escalation

N/A
2021-04-14< 7.3.0

BuddyPress <= 7.2.1 - Missing Authorization to Group Creation

N/A
2021-08-18< 9.1.1

BuddyPress <= 9.0.0 - Information Disclosure via REST API

N/A
2021-08-18< 9.1.1

BuddyPress <= 9.0.0 - SQL Injection

N/A
< 1.7.2

BuddyPress 1.7.1 - Multiple SQL Injections

N/A
< 1.2.10

wpscan.com

N/A
< 2.3.5

wpscan.com

N/A
≥ 2.0 and ≤ 2.7.3

BuddyPress 2.0-2.7.3 - Arbitrary File Deletion

N/A
< 5.1.1

BuddyPress &lt; 5.1.1 - Denial of Service

N/A
≥ 5.0.0 and ≤ 5.1.1

BuddyPress 5.0.0-5.1.1 - Private Data Exposure via REST API

N/A
< 6.4.0

BuddyPress &lt; 6.4.0 - Lack of Capability Check on Profile Page

N/A
< 7.2.1

wpscan.com

N/A
< 7.2.1

BuddyPress &lt; 7.2.1 - Manage BuddyPress Member Types

N/A
< 7.2.1

wpscan.com

N/A
< 7.2.1

wpscan.com

N/A
< 7.3.0

wpscan.com

N/A
< 9.1.1

BuddyPress &lt; 9.1.1 - SQL Injections

N/A
< 9.1.1

BuddyPress &lt; 9.1.1 - Activation Key Disclosure

N/A
2011-09-26≤ 1.2.10

WordPress BuddyPress Plugin 1.2.10 - HTML Injection Vulnerability

N/A
2015-05-15< 1.2.10

WordPress BuddyPress Plugin <= 1.2.9 - SQL Injection

N/A
2015-05-15< 1.7.2

WordPress BuddyPress Plugin <= 1.7.1 - Multiple SQL Injections

N/A
2015-11-12< 2.3.5

WordPress BuddyPress Plugin <= 2.3.4 - Privilege Escalation

N/A
2016-12-23< 2.7.4

WordPress BuddyPress Plugin <= 2.7.3 - Arbitrary File Deletion

N/A
2020-11-29< 6.4.0

WordPress BuddyPress plugin <= 6.3.0 - Excessive user capabilities in possible rich text fields vulnerability