BuddyPress <= 5.1.0 - Denial of Service
2019-12-23 00:00
nomnomStrategic Overview
Vulnerability Overview
The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.
Technical Analysis
REMEDIATION: Update to version 5.1.1, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C