BuddyPress

BuddyPress has 27 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2026; 26 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.9, and the most serious one scores 10.0 out of 10. Severity breakdown: 3 critical and 8 high. 2021 was the busiest year with 10 disclosures.

The most common weakness is Cross-Site Scripting, behind 5 of the records (19%). Other recurring categories include Incorrect Authorization, Improper Access Control.

26 of the records (96%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

18 independent researchers contributed these findings, most of them (6) reported by Kien Hoang. BuddyPress is installed on roughly 90,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891023.04.2009Today27.03.20129.8BuddyPress - 1.5-1.5.4 - SQL Injection CVSS 9.8 · 27.03.201205.02.20146.5BuddyPress <= 1.9.1 - Authorization Bypass CVSS 6.5 · 05.02.201401.08.20146.4BuddyPress <= 1.9.1 - Stored Cross-Site Scripting CVSS 6.4 · 01.08.201411.11.20158.8BuddyPress <= 2.3.4 - Privilege Escalation CVSS 8.8 · 11.11.201523.12.201610.0BuddyPress 2.0 - 2.7.3 - Unauthenticated Arbitrary File Deletion CVSS 10.0 · 23.12.201623.12.20195.4BuddyPress <= 5.1.0 - Denial of Service CVSS 5.4 · 23.12.201902.01.20207.5BuddyPress <= 5.1.1 - Sensitive Information Disclosure CVSS 7.5 · 02.01.202027.11.20206.4BuddyPress <= 6.3.0 - Insufficient Input Validation CVSS 6.4 · 27.11.202007.03.20216.5BuddyPress <= 7.2.0 - Authorization Bypass to Private Message Disclosure CVSS 6.5 · 07.03.202116.03.20214.6BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation CVSS 4.6 · 16.03.20218.8BuddyPress 5.0.0-7.2.0 - Privilege Escalation via REST API CVSS 8.8 · 16.03.202117.03.20215.4BuddyPress <= 7.2.0 - Authorization Bypass to Friend Invite CVSS 5.4 · 17.03.202114.04.20215.4BuddyPress <= 7.2.1 - Missing Authorization to Group Creation CVSS 5.4 · 14.04.20215.4BuddyPress <= 7.2.1 - Missing Authorization to Unauthorized Group Access CVSS 5.4 · 14.04.20218.8BuddyPress <= 7.2.1 - Insufficient Privilege De-escalation CVSS 8.8 · 14.04.20215.4BuddyPress <= 7.2.1 - Missing Authorization to Private Post Activity CVSS 5.4 · 14.04.202118.08.20219.8BuddyPress <= 9.0.0 - SQL Injection CVSS 9.8 · 18.08.20218.8BuddyPress <= 9.0.0 - Information Disclosure via REST API CVSS 8.8 · 18.08.202126.12.20236.4BuddyPress <= 11.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 26.12.202303.05.20246.4BuddyPress <= 12.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 03.05.202411.06.20246.4BuddyPress <= 12.4.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 11.06.202424.10.20248.1BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal CVSS 8.1 · 24.10.202427.09.20255.3BuddyPress <= 14.3.4 - Missing Authorization CVSS 5.3 · 27.09.202522.01.20267.3BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution CVSS 7.3 · 22.01.202613.07.20264.3BuddyPress <= 14.4.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure CVSS 4.3 · 13.07.202629.07.20267.5BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data CVSS 7.5 · 29.07.202610.09.20264.3BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion CVSS 4.3 · 10.09.2026

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage96%
Open

1

Fixed

26

Get automatic notifications for all BuddyPress vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2026-1360

BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data

Read the full analysis

Vulnerability Records

27 records
2026-09-10 21:43CVE-2024-12145
4.3
Medium
Brian MungaiYes
2026-07-29 15:16CVE-2026-1360
7.5
High
Vincent Theriault-LaineNo
2026-07-13 00:00CVE-2026-8155
4.3
Medium
Mustafa AhmedYes
2026-01-22 18:30CVE-2024-11976
7.3
High
mikemyersYes
2025-09-27 00:00CVE-2025-62022
5.3
Medium
Asim Alshaya (AsimCr0)Yes
2024-10-24 17:56CVE-2024-10011
8.1
High
Dominik Dziura (Domons)Yes
2024-06-11 12:16CVE-2024-4892
6.4
Medium
wesley (wcraft)Yes
2024-05-03 00:00CVE-2024-3974
6.4
Medium
wesley (wcraft)Yes
2023-12-26 00:00CVE-2023-50880
6.4
Medium
Rafie MuhammadYes
2021-08-18 00:00N/A
9.8
Critical
David CavinsYes
Showing 1–10 of 27 reports
BuddyPress banner
Latestv14.5.2
4.1(375)
82/100
Last Updated
2026-07-29 (2mo ago)
Active Installs
90,000+
Downloads
13,901,236
Requires WP
6.1+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2009-04-23 (18y ago)

Are you looking for modern, robust, and sophisticated social network software? BuddyPress is a suite of components that are common to a typical social network, and allows for great add-on features through WordPress’s extensive plugin system. Aimed at site builders & developers, BuddyPress is focused on ease of integration, ease of use, and extensibility. It is deliberately powerful yet unbelievably simple social network software, built by contributors to WordPress. Members can register on your site to create user profiles, have private conversations, make social connections, create and interact in groups, and much more. Truly a social network in a box, BuddyPress helps you build a home for your company, school, sports team, or other niche community. Built with developers in mind BuddyPress helps site builders & developers add community features to their websites. It comes with a robust theme compatibility API that does its best to make every BuddyPress content page look and feel right with just about any WordPress theme. You will likely need to adjust some styling on your own to make everything look pristine. BuddyPress themes are just WordPress themes with additional templates, and with a little work, you could easily create your own, too! A handful of BuddyPress-specific themes are readily available for download from WordPress.org, and lots more are available from third-party theme authors. BuddyPress also comes with built-in support for Akismet and bbPress, two very popular and very powerful WordPress plugins. If you’re using either, visit their settings pages and ensure everything is configured to your liking. The BuddyPress Add-ons WordPress.org is home to some amazing Add-ons for BuddyPress, including: BP Attachments BP Classic NB: BP Classic is a backwards compatibility Add-on for BuddyPress 12.0 and up bringing back the BP Legacy URL parser, the BP Default theme and BP Legacy widgets. Go to BuddyPress profile on WordPress.org to find them all! Join our community If you’re interested in contributing to BuddyPress, we’d love to have you. Head over to the BuddyPress Documentation site to find out how you can pitch in. BuddyPress is available in many languages thanks to the volunteer efforts of individuals all around the world. Check out our translations page on the BuddyPress Documentation site for more details. If you are a polyglot, please consider helping translate BuddyPress into your language. Growing the BuddyPress community means better software for everyone!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C