CVE-2020-37233
BuddyPress version 6.2.0 and earlier contains a stored cross-site scripting flaw that enables authenticated users with moderator-level access to execute arbitrary scripts by injecting malicious code into the figure parameter within wp:html blocks. When site administrators or other privileged users view pages containing this injected content, attackers can leverage iframe elements and event handlers to compromise user sessions and carry out persistent phishing campaigns.
Based on public CVE data (MITRE/NVD).