Extension WordPress
Vulnérabilités BuddyPress
Cette page rassemble les failles publiées pour BuddyPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BuddyPress
24 fiches
BuddyPress <= 14.3.3 – Unauthenticated Arbitrary Shortcode Execution
The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a…
*-14.3.3
14.3.4
22/01/2026
BuddyPress <= 14.3.4 – Missing Authorization
The BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 14.3.4. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-14.3.4
14.4.0
27/09/2025
BuddyPress <= 14.1.0 – Authenticated (Subscriber+) Directory Traversal
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on…
*-14.1.0
14.2.1
24/10/2024
BuddyPress <= 12.4.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-12.5.0
12.5.1
11/06/2024
BuddyPress <= 12.4.0 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-12.4.0
12.4.1
03/05/2024
BuddyPress <= 11.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Members/Groups block properties in all versions up to, and including, 11.3.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-11.3.1
11.3.2
26/12/2023
BuddyPress <= 9.0.0 – Information Disclosure via REST API
The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and including 9.0.0. This is due to the plugin disclosing the activation key from responses of the create_item method in the…
*-9.0.0
9.1.1
18/08/2021
BuddyPress <= 9.0.0 – SQL Injection
The BuddyPress plugin for WordPress is vulnerable to generic SQL Injection via the ‘BP_Notifications_Notification::get_order_by_sql()' and 'BP_Invitation::get_order_by_sql()’ parameters in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-9.0.0
9.1.1
18/08/2021
BuddyPress <= 7.2.1 – Missing Authorization to Unauthorized Group Access
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group REST-API Endpoint. This makes it possible for authenticated attackers to join…
*-7.2.1
7.3.0
14/04/2021
BuddyPress <= 7.2.1 – Missing Authorization to Private Post Activity
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the activity REST-API Endpoint. This makes it possible for authenticated attackers to favorite…
*-7.2.1
7.3.0
14/04/2021
BuddyPress <= 7.2.1 – Insufficient Privilege De-escalation
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the can_user_delete_or_update( ) function from versions starting at 7.0.0 to 7.2.1. This makes it possible for recently demoted user to modify…
*-7.2.1
7.3.0
14/04/2021
BuddyPress <= 7.2.1 – Missing Authorization to Group Creation
The BuddyPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 7.2.1. This is due to missing authorization validation on the group membership REST-API Endpoint. This makes it possible for authenticated attackers to…
*-7.2.1
7.3.0
14/04/2021
BuddyPress <= 7.2.0 – Authorization Bypass to Friend Invite
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the buddypress/v1/groups/invites REST-API endpoint in versions up to, and including, 7.2.0. This makes it possible for a member to invite another…
*-7.2.0
7.2.1
17/03/2021
BuddyPress 5.0.0-7.2.0 – Privilege Escalation via REST API
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST…
5.0.0-7.2.0
7.2.1
16/03/2021
BuddyPress – 7.0.0 – 7.2.0 – Insufficient Privilege De-escalation
The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 – 7.2.0. This allowed subscriber level users to modify…
[7.0.0, 7.2.1)
7.2.1
16/03/2021
BuddyPress <= 7.2.0 – Authorization Bypass to Private Message Disclosure
The BuddyPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the BuddyPress Nouveau and the BuddyPress REST API /buddypress/v1/messages endpoint in versions 5.0.0 – 7.2.0. This makes it possible for non-privileged…
*-7.2.0
7.2.1
07/03/2021
BuddyPress <= 6.3.0 – Insufficient Input Validation
The BuddyPress plugin for WordPress is vulnerable to Insufficient Input Validation in versions up to, and including, 6.3.0. This is due to missing authorization checks and proper sanitization on a users profile page. This makes it possible for…
[*, 6.4.0)
6.4.0
27/11/2020
BuddyPress <= 5.1.1 – Sensitive Information Disclosure
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
*-5.1.1
5.1.2
02/01/2020
BuddyPress <= 5.1.0 – Denial of Service
The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.
*-5.1.0
5.1.1
23/12/2019
BuddyPress 2.0 – 2.7.3 – Unauthenticated Arbitrary File Deletion
The BuddyPress plugin for WordPress is vulnerable to Arbitrary File Deletion in versions 2.0 – 2.7.3. This allows unauthenticated attackers to delete the contents of arbitrary files on the server, which can lead to site takeover
2.0-2.7.3
2.7.4
23/12/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.