Extension WordPress
Vulnérabilités BuddyPress, page 2
Cette page rassemble les failles publiées pour BuddyPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BuddyPress
24 fiches
BuddyPress <= 2.3.4 – Privilege Escalation
The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This makes it possible for authenticated attackers to execute otherwise privilege restricted actions and bypass capability checks.
*-2.3.4
2.3.5
11/11/2015
BuddyPress <= 1.9.1 – Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the BuddyPress plugin before 1.9.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the name field to groups/create/step/group-details. NOTE: this can be exploited without authentication by leveraging…
*-1.9.1
1.9.2
01/08/2014
BuddyPress <= 1.9.1 – Authorization Bypass
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. An attacker could exploit this vulnerability to modify the name,…
[*, 1.9.2)
1.9.2
05/02/2014
BuddyPress – 1.5-1.5.4 – SQL Injection
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.
1.5-1.5.4
1.5.5
27/03/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.