BuddyPress

BuddyPress is social network software aimed at site builders and developers, with a focus on ease of integration, ease of use, and extensibility. It allows members to register on a site to create user profiles, have private conversations, make social connections, create and interact in groups, and more. BuddyPress also comes with built-in support for Akismet and bbPress, and has a robust theme compatibility API to make every BuddyPress content page look and feel right with just about any WordPress theme. The software is built by contributors to WordPress and is deliberately powerful yet simple.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in BuddyPress 14.3.4

    Fixed

    The BuddyPress add-on for WordPress has a security flaw that allows unauthorized individuals to access it without proper authorization. This vulnerability affects all versions of the add-on, includin...

    Read More
  • Access violation vulnerability in BuddyPress 14.1.0

    Fixed

    The BuddyPress plugin for WordPress has a security flaw that allows hackers to access files in other directories and upload files to places they shouldn't be able to. This can be done by attackers wh...

    Read More
  • Input validation vulnerability in BuddyPress 12.5.0

    Fixed

    The BuddyPress add-on for WordPress has a security issue that allows hackers to inject harmful code into web pages. This can be done by taking advantage of a flaw in the way the plugin handles user i...

    Read More
  • Input validation vulnerability in BuddyPress 12.4.0

    Fixed

    The BuddyPress add-on for WordPress has a security issue that allows hackers to insert harmful scripts into web pages. This can happen when a user with certain permissions adds their name to a page.

    Read More
  • Input validation vulnerability in BuddyPress 11.3.1

    Fixed

    The BuddyPress plugin for WordPress contains a vulnerability that could allow authenticated attackers with certain permissions to inject malicious code into pages. This code would run whenever the pa...

    Read More
  • Denial of Service vulnerability in BuddyPress 5.1.0

    Fixed

    The BuddyPress plugin for WordPress is vulnerable to Denial of Service, which means it can be taken over, in versions up to and including 5.1.0. This makes it possible for someone with access to the ...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.1

    Fixed

    The BuddyPress plugin, which is used with WordPress, is vulnerable in versions up to 7.2.1. This means it can be exploited by attackers. If they are already signed in, they can join or ask to join gr...

    Read More
  • Authentication vulnerability in BuddyPress 1.9.2

    Fixed

    The Buddypress plugin for WordPress

    Read More
  • Access violation vulnerability in BuddyPress 7.2.0

    Fixed

    BuddyPress is a plugin for WordPress that helps people build a community website. Unfortunately

    Read More
  • Input validation vulnerability in BuddyPress 1.9.1

    Fixed

    Cross-site scripting (XSS) is a security vulnerability that can allow attackers to inject malicious code into websites. The BuddyPress plugin

    Read More
  • Access violation vulnerability in BuddyPress 9.0.0

    Fixed

    The BuddyPress plugin for WordPress is a tool used to add extra features to WordPress websites. In versions up to and including 9.0.0, there is an issue that can be exploited by non-privileged attack...

    Read More
  • Access violation vulnerability in BuddyPress 2.3.4

    Fixed

    The BuddyPress plugin for WordPress is not secure in versions up to 2.3.4. This means that people with certain levels of access can perform actions that are normally restricted and not allowed.

    Read More
  • Access violation vulnerability in BuddyPress 5.1.1

    Fixed

    In BuddyPress

    Read More
  • Access violation vulnerability in BuddyPress 7.2.1

    Fixed

    The BuddyPress plugin is a tool used for WordPress websites. However, versions 7.0.0 - 7.2.0 had an issue with how they handled turning administrators into subscribers. This issue caused a security r...

    Read More
  • Access violation vulnerability in BuddyPress 2.7.3

    Fixed

    . The BuddyPress plugin for WordPress is a security issue in versions 2.0 to 2.7.3. This means that unauthenticated people can delete the contents of any file on the server, which could potentially al...

    Read More
  • Input validation vulnerability in BuddyPress 6.4.0

    Fixed

    The BuddyPress plugin for WordPress has a security issue that could allow malicious users to execute Cross-Site Scripting attacks. This issue affects versions of BuddyPress up to and including 6.3.0,...

    Read More
  • Input validation vulnerability in BuddyPress 9.0.0

    Fixed

    The BuddyPress plugin for WordPress is a software that has a security flaw. If it is used in versions up to 9.0.0, it can be susceptible to attack. This means that an unauthorized person could use th...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.1

    Fixed

    The BuddyPress plugin for WordPress is at risk of unauthorized access in versions up to and including 7.2.1. This is because the activity REST-API Endpoint does not have proper authorization validati...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.1

    Fixed

    The BuddyPress plugin for WordPress is vulnerable to a security issue, which allows people who have been recently demoted to modify the groups that they originally created. This vulnerability affects...

    Read More
  • Input validation vulnerability in BuddyPress 1.5.4

    Fixed

    A security flaw in the BuddyPress plugin version 1.5.x (up to 1.5.5) in WordPress could allow someone to remotely access and manipulate the website's data by entering specially crafted code into the "...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.1

    Fixed

    The BuddyPress plugin for WordPress is vulnerable to a security issue if you are using versions up to 7.2.1. This issue is caused by a lack of authorization validation on a certain feature of the sof...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.0

    Fixed

    The BuddyPress plugin for WordPress, used up to and including version 7.2.0, has an issue that allows people to invite someone to join a group even if the group requires that the people be friends fi...

    Read More
  • Access violation vulnerability in BuddyPress 7.2.0

    Fixed

    The BuddyPress plugin for WordPress, versions 5.0.0 to 7.2.0, has a security vulnerability that allows people who should not be able to access it to read private messages in conversations that they a...

    Read More