Known Vulnerabilities for BuddyPress by Buddypress
Listed below are 10 of the newest known vulnerabilities associated with "BuddyPress" by "Buddypress".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53675 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenti... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53674 json | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-53673 json | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticat... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-40773 json | Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-15287 json | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the orde... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-13450 json | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vul... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-4653 json | The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' pa... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2025-62022 json | Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14... | Not Provided | 2025-10-22 | 2026-04-28 |
| CVE-2025-23798 json | Not Provided | 2025-01-22 | 2026-04-23 | |
| CVE-2024-49247 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registr... | Not Provided | 2024-10-16 | 2026-04-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Buddypress | Buddypress | 5.1.2 | |||
| Application | Buddypress | Buddypress | 3.0 | |||
| Application | Buddypress | Buddypress | 2.9.3 | |||
| Application | Buddypress | Buddypress | 2.9.2 | |||
| Application | Buddypress | Buddypress | 2.9.0 | |||
| Application | Buddypress | Buddypress | 2.9.0 | |||
| Application | Buddypress | Buddypress | 2.8.1 | |||
| Application | Buddypress | Buddypress | 2.8.0 | |||
| Application | Buddypress | Buddypress | 2.8.0 | |||
| Application | Buddypress | Buddypress | 2.7.4 | |||
| Application | Buddypress | Buddypress | 2.7.1 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.7.0 | |||
| Application | Buddypress | Buddypress | 2.5.0 | |||
| Application | Buddypress | Buddypress | 2.4.2 | |||
| Application | Buddypress | Buddypress | 2.4.0 | |||
| Application | Buddypress | Buddypress | 2.3.5 | |||
| Application | Buddypress | Buddypress | 2.3.4 | |||
| Application | Buddypress | Buddypress | 2.3.3 |