Vulnerabilities > Buddypress > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-10011 Path Traversal vulnerability in Buddypress
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter.
network
low complexity
buddypress CWE-22
8.1
2021-03-26 CVE-2021-21389 Unspecified vulnerability in Buddypress
BuddyPress is an open source WordPress plugin to build a community site.
network
low complexity
buddypress
8.8
2020-02-24 CVE-2020-5244 Information Exposure vulnerability in Buddypress 5.0.0/5.1.0/5.1.1
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed.
network
low complexity
buddypress CWE-200
7.5