BuddyPress is a community and social-networking plugin for WordPress that extends the platform with member profiles, activity streams, and group functionality, placing it across a broad base of WordPress installations. The vulnerability exposure recurs through application-layer input-handling and access-control weaknesses, including cross-site scripting, SQL injection, path traversal, and improper information disclosure, which are characteristic of web plugins operating in a shared hosting environment where input sanitization and authorization boundaries are critical. Public exploit code has frequently been made available for identified flaws, underscoring the appeal of WordPress plugins to attackers seeking to compromise installations at scale. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buddypress over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21389HIGH BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtai | Mar 26, 2021 | 8.8 | 46 | NO | YES |
CVE-2026-53673HIGH BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message thread | Jun 10, 2026 | 8.1 | 34 | NO | NO |
CVE-2012-2109HIGH SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter | Sep 4, 2012 | 7.5 | 33 | NO | YES |
CVE-2014-1889MEDIUM The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permiss | Apr 10, 2018 | 6.5 | 32 | NO | YES |
CVE-2026-53674HIGH BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to mani | Jun 10, 2026 | 7.1 | 30 | NO | NO |
CVE-2024-10011HIGH The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated | Oct 25, 2024 | 8.1 | 27 | NO | NO |
CVE-2024-11976HIGH The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to e | Jan 23, 2026 | 7.3 | 25 | NO | NO |
CVE-2025-62022HIGH Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4. | Oct 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-53675MEDIUM BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete fri | Jun 10, 2026 | 4.3 | 22 | NO | NO |
CVE-2020-5244HIGH In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version | Feb 24, 2020 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buddypress.
Media articles that mention a CVE ID that affects a product developed by Buddypress — matched by CVE ID, not by vendor name.