CVE · High

CVE-2024-11976 — BuddyPress [buddypress] < 14.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-11976 BuddyPress [buddypress] < 14.3.4 Improper Control of Generation of Code ('Code Injection') High 7.3 < 14.3.4 14.3.4 2026-01-22

CVE-2024-11976

BuddyPress versions before 14.3.4 contain a vulnerability allowing unauthenticated attackers to execute arbitrary shortcodes. The plugin fails to properly validate user input before processing shortcodes through the do_shortcode function, enabling malicious actors to trigger unintended code execution. This flaw affects all versions up to and including 14.3.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.