CVE · Medium

CVE-2024-9207 — BuddyPress Docs [buddypress-docs] < 2.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9207 BuddyPress Docs [buddypress-docs] < 2.2.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.2.4 2.2.4 2024-10-07

CVE-2024-9207

The BuddyPress Docs plugin for WordPress contains a security flaw where URLs are not properly sanitized, allowing malicious actors to embed executable code within legitimate links. This vulnerability affects all versions up to and including 2.2.3, enabling unauthenticated attackers to inject arbitrary scripts that can be executed if a user clicks on the link.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.