Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total8
Critical0
High5
Medium3
Reset
Showing 1-8 of 8 records
Threat Entry Updated 2026-06-17

CVE-2026-53673 - Buddypress Plugin

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reused by the update and delete handlers, to read, reply to, or delete any user's private messages.

PLUGIN Buddypress

CVE-2026-53673

HIGH CVSS 8.6 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53674 - Buddypress Plugin

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mentions whose metacharacters pass through esc_sql unescaped and are inserted into an unprepared REGEXP query against the users table, enabling boolean-based inference of usernames and denial of service through catastrophic backtracking.

PLUGIN Buddypress

CVE-2026-53674

HIGH CVSS 7.1 2026-06-10
Threat Entry Updated 2026-06-17

CVE-2026-53675 - Buddypress Plugin

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers can query the friends endpoint with an arbitrary user_id because the get_items_permissions_check method only verifies that the requester is logged in and never checks ownership of the requested list, resulting in disclosure of users' private social connections.

PLUGIN Buddypress

CVE-2026-53675

MEDIUM CVSS 5.3 2026-06-10
Threat Entry Updated 2026-01-26

CVE-2024-11976 - The Buddypress Plugin

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

PLUGIN The Buddypress

CVE-2024-11976

HIGH CVSS 7.3 2026-01-23
Threat Entry Updated 2024-11-06

CVE-2024-10011 - Buddypress Plugin

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enables file uploads to directories outside of the web root. Depending on server configuration it may be possible to upload files with double extensions. This vulnerability only affects Windows.

PLUGIN Buddypress

CVE-2024-10011

HIGH CVSS 8.1 2024-10-25
Threat Entry Updated 2025-06-05

CVE-2024-4892 - Buddypress Plugin

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddypress

CVE-2024-4892

MEDIUM CVSS 6.4 2024-06-12
Threat Entry Updated 2025-06-05

CVE-2024-3974 - Buddypress Plugin

The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_name’ parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Buddypress

CVE-2024-3974

MEDIUM CVSS 6.4 2024-05-14
Threat Entry Updated 2024-11-21

CVE-2021-21389 - Buddypress Plugin

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

PLUGIN Buddypress

CVE-2021-21389

HIGH CVSS 8.1 2021-03-26
Scroll to top