Extension WordPress
Vulnérabilités Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
Cette page rassemble les failles publiées pour Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
14 fiches
Youzify <= 1.3.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-1.3.6
1.3.7
17/04/2026
Youzify <= 1.3.7 – Authenticated (Subscriber+) Server-Side Request Forgery
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers,…
*-1.3.7
Non indiqué
27/12/2025
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 – Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and…
*-1.3.3
1.3.4
24/01/2025
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 – Missing Authorization to Authenticated (Subscriber+) Limited Options Update
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and…
*-1.3.4
1.3.5
24/01/2025
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all…
*-1.3.2
1.3.3
24/01/2025
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to…
*-1.3.0
1.3.1
09/10/2024
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 – Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up…
*-1.3.0
1.3.1
09/10/2024
Youzify <= 1.2.6 – Missing Authorization
The Youzify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.2.6
1.2.8
24/07/2024
Youzify <= 1.2.5 – Authenticated (Contributor+) SQL Injection
The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-1.2.5
1.2.6
04/07/2024
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 – Authenticated (Contributor+) SQL Injection
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient…
*-1.2.5
1.2.6
19/06/2024
Youzify <= 1.2.2 – Insecure Direct Object Reference
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.2 due to missing validation on a…
*-1.2.2
1.2.3
03/11/2023
Youzify <= 1.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-1.2.1
1.2.2
24/01/2023
Youzify <= 1.1.9 – SQL Injection
The Youzify Plugin for WordPress is vulnerable to SQL injection via the 'youzify_media_pagination' AJAX action in versions before 1.2.0 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query. This…
*-1.1.9
1.2.0
13/07/2022
Youzify <= 1.0.6 – Stored Cross-Site Scripting
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it,…
*-1.0.6
1.0.7
28/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.