BuddyPress <= 5.1.0 - Denial of Service

2019-12-23 00:00
nomnom

Strategic Overview

Status
Patched in 5.1.1
Affected PluginBuddyPress
Affected Version<= 5.1.0
CVSS5.4Medium
CVEN/A
View all BuddyPress vulnerabilities

Vulnerability Overview

The BuddyPress plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers to remove another user’s avatar and/or remove any empty folder.

Technical Analysis

REMEDIATION: Update to version 5.1.1, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C