BP Email Assign Templates
BP Email Assign Templates has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.8 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Improper Input Validation.
Every one of the 4 issues recorded for BP Email Assign Templates has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, most of them (2) reported by ch4r0n. BP Email Assign Templates is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-28874BP Email Assign Templates <= 1.7 - Authenticated (Admin+) Arbitrary Option Deletion
Read the full analysisVulnerability Records
BP Email Assign Templates
Author
shanebp
This BuddyPress / BuddyBoss plugin allows site administrators to assign template options to individual BuddyPress Emails. It requires BuddyPress 2.5.1 or higher. It: provides a screen for creating template options provides a meta-box for assigning template options to each BuddyPress Email filters each BuddyPress email so that it uses the assigned template It does NOT include: templates an interface for creating templates For more info on BuddyPress Emails, visit: https://codex.buddypress.org/emails/ For more info on this plugin, visit: https://www.philopress.com/products/bp-email-assign-templates/ For more BuddyPress plugins, visit: https://www.philopress.com/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C