Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BuddyPress — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in BuddyPress, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability information for BuddyPress, a popular WordPress plugin developed by the BuddyPress vendor, categorized under software weakness types such as cross-site scripting or injection flaws. It collects publicly disclosed security issues, vendor advisories, and exploit details covering the period from the plugin’s initial release through the present day, ensuring a comprehensive historical view of its security posture. Visitors can use this resource to track the vendor’s official security advisories as they are published, gain a deeper understanding of specific weakness classes like broken access control or improper input validation, and look up the complete vulnerability history of the BuddyPress product to assess past and present risks. By consolidating these diverse data points, the page serves as a centralized reference point for developers, security researchers, and site administrators seeking to evaluate the safety of their BuddyPress installations. The content is structured to facilitate quick identification of critical issues while also providing context for lower-severity findings, allowing users to make informed decisions about patching and mitigation strategies. All listed items are sourced from verified public records and official vendor statements to maintain accuracy and reliability. This approach ensures that users can quickly identify potential threats without sifting through fragmented information across multiple sources. The aggregation process focuses on clarity and completeness, making it easier to understand the overall security landscape surrounding this widely used WordPress extension.

Vendor: buddypress

CVE IDTitleCVSSSeverityPublished
CVE-2026-8155 BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR --2026-07-31
CVE-2026-1360 BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data CWE-502 7.5 High2026-07-30
CVE-2026-53675 BuddyPress 14.4.0 Friends List IDOR via REST API CWE-639 4.3 Medium2026-06-09
CVE-2026-53673 BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter CWE-639 8.1 High2026-06-09
CVE-2026-53674 BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution CWE-943 7.1 High2026-06-09
CVE-2020-37233 WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting CWE-79 6.4 Medium2026-05-16
CVE-2024-11976 BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution CWE-94 7.3 High2026-01-23
CVE-2025-62022 WordPress BuddyPress plugin <= 14.3.4 - Broken Access Control vulnerability CWE-862 7.5 High2025-10-22
CVE-2024-10011 BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal CWE-22 8.1 High2024-10-25
CVE-2024-4892 BuddyPress <= 12.4.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-06-12
CVE-2024-3974 BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-05-09
CVE-2023-50880 WordPress BuddyPress Plugin <= 11.3.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-12-29
CVE-2021-21389 BuddyPress privilege escalation via REST API CWE-863 8.1 High2021-03-26
CVE-2020-5244 Private data exposure via REST API in BuddyPress CWE-284 8.0 High2020-02-24

All 14 known CVE vulnerabilities affecting BuddyPress with full Chinese analysis, references, and POCs where available.