Input validation vulnerability in Buddyboss Platform 2.7.70

The Buddyboss Platform plugin for WordPress has a security issue called Stored Cross-Site Scripting. This is because it does not properly clean up user input and output. This vulnerability affects all versions up to 2.7.70, and can be used by anyone with Subscriber-level access or higher to insert harmful web scripts on pages. These scripts will run whenever someone visits the affected page.

Detected in:

Buddyboss Platform fixed vulnerable versions: >= * <= 2.7.70

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.