Access violation vulnerability in BuddyPress 7.2.0

The BuddyPress plugin for WordPress, versions 5.0.0 to 7.2.0, has a security vulnerability that allows people who should not be able to access it to read private messages in conversations that they are not part of. This is because there is no security check in place to make sure it is only available to authorized users. This vulnerability could be exploited by a non-privileged attacker.

Detected in:

BuddyPress fixed vulnerable versions: >= * <= 7.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.