Vulnerabilities > Buddypress > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-25 | CVE-2024-10011 | Path Traversal vulnerability in Buddypress The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. | 8.1 |
2021-03-26 | CVE-2021-21389 | Unspecified vulnerability in Buddypress BuddyPress is an open source WordPress plugin to build a community site. | 8.8 |
2020-02-24 | CVE-2020-5244 | Information Exposure vulnerability in Buddypress 5.0.0/5.1.0/5.1.1 In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. | 7.5 |