CVE Database /
CVE-2024-9207
CVE · Medium
CVE-2024-9207 — BuddyPress Docs [buddypress-docs] < 2.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9207
|
BuddyPress Docs [buddypress-docs] < 2.2.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.2.4
|
2.2.4 |
2024-10-07 |
—
|
CVE-2024-9207
The BuddyPress Docs plugin for WordPress contains a security flaw where URLs are not properly sanitized, allowing malicious actors to embed executable code within legitimate links. This vulnerability affects all versions up to and including 2.2.3, enabling unauthenticated attackers to inject arbitrary scripts that can be executed if a user clicks on the link.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings