CVE · Medium

CVE-2024-4886 — Buddyboss Platform [buddyboss-platform] < 2.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4886 Buddyboss Platform [buddyboss-platform] < 2.6.0 Authorization Bypass Through User-Controlled Key Medium 4.3 < 2.6.0 2.6.0 2024-05-15

CVE-2024-4886

The Buddyboss Platform plugin for WordPress contains an insecure direct object reference vulnerability in versions up to 2.5.91 affecting the new_activity_comment AJAX action. The flaw stems from insufficient validation of user-supplied input in a key parameter, allowing any authenticated user with subscriber privileges or higher to post comments on private posts that they should not have access to.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.