Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Buddypress

First CVE: Sep 4, 2012Active for: 14 yearsTotal CVEs: 16
48.2
VTI Score
High

BuddyPress is a community and social-networking plugin for WordPress that extends the platform with member profiles, activity streams, and group functionality, placing it across a broad base of WordPress installations. The vulnerability exposure recurs through application-layer input-handling and access-control weaknesses, including cross-site scripting, SQL injection, path traversal, and improper information disclosure, which are characteristic of web plugins operating in a shared hosting environment where input sanitization and authorization boundaries are critical. Public exploit code has frequently been made available for identified flaws, underscoring the appeal of WordPress plugins to attackers seeking to compromise installations at scale. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Buddypress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2012
13 years ago
Most Recent CVE
Jun 10, 2026
45 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-21389HIGH
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtai
Mar 26, 20218.846NOYES
CVE-2026-53673HIGH
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message thread
Jun 10, 20268.134NONO
CVE-2012-2109HIGH
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter
Sep 4, 20127.533NOYES
CVE-2014-1889MEDIUM
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permiss
Apr 10, 20186.532NOYES
CVE-2026-53674HIGH
BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to mani
Jun 10, 20267.130NONO
CVE-2024-10011HIGH
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated
Oct 25, 20248.127NONO
CVE-2024-11976HIGH
The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to e
Jan 23, 20267.325NONO
CVE-2025-62022HIGH
Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.
Oct 22, 20257.524NONO
CVE-2026-53675MEDIUM
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete fri
Jun 10, 20264.322NONO
CVE-2020-5244HIGH
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version
Feb 24, 20207.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
50%
50%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (87.5%)
Unknown2 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High0 (0.0%)
Unknown2 (12.5%)
User Interaction
None10 (62.5%)
Unknown2 (12.5%)
Required4 (25.0%)
Privileges Required
Low10 (62.5%)
High0 (0.0%)
None4 (25.0%)
Unknown2 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 96th percentile
ExploitDB
2 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Buddypress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Buddypress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Buddypress's Products

View all 6 CNAs →

Top CWEs