CVE · Medium

CVE-2020-37233 — BuddyPress [buddypress] <= 6.2.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-37233 BuddyPress [buddypress] <= 6.2.0 (unfixed) Medium 6.4 < 6.2.0 6.2.0 2026-05-16

CVE-2020-37233

BuddyPress version 6.2.0 and earlier contains a stored cross-site scripting flaw that enables authenticated users with moderator-level access to execute arbitrary scripts by injecting malicious code into the figure parameter within wp:html blocks. When site administrators or other privileged users view pages containing this injected content, attackers can leverage iframe elements and event handlers to compromise user sessions and carry out persistent phishing campaigns.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.