Pricing
Case studies
Login
Start trial
BuddyPress
BuddyPress
Developer
14.4.0
Latest version
100,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
15 patched
7 Mitigation rules
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 14.3.3
23/01/2026
Broken Access Control vulnerability
<= 14.3.4
27/09/2025
Authenticated (Subscriber+) Directory Traversal vulnerability
<= 14.1.0
24/10/2024
Authenticated (Subscriber+) Stored Cross-Site Scripting vulnerability
<= 12.4.0
05/05/2024
Cross Site Scripting (XSS) vulnerability
<= 11.3.1
26/12/2023
Privilege Escalation vulnerability
<= 7.2.0
17/03/2021
Excessive user capabilities in possible rich text fields vulnerability
<= 6.3.0
29/11/2020
Arbitrary File Deletion
<= 2.7.3
23/12/2016
Privilege Escalation
<= 2.3.4
12/11/2015
Multiple SQL Injections
<= 1.7.1
15/05/2015
SQL Injection
<= 1.2.9
15/05/2015
Privilege Escalation
<= 1.9.1
11/02/2014
XSS
<= 1.9.1
07/02/2014
Remote SQL Injection
<= 1.5.5
31/03/2012
HTML Injection Vulnerability
<= 1.2.10
26/09/2011