CVE · Critical

CVE-2026-56032 — Buddyboss Platform [buddyboss-platform] < 3.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-56032 Buddyboss Platform [buddyboss-platform] < 3.0.5 Deserialization of Untrusted Data Critical 9.8 < 3.0.5 3.0.5 2026-06-23

CVE-2026-56032

Authenticated users with subscriber-level access and above can inject malicious PHP objects into the BuddyBoss Platform plugin for WordPress through versions 3.0.4 and below by exploiting a deserialization vulnerability in untrusted input. This weakness allows potential attackers to introduce arbitrary PHP functionality, which could be leveraged further if additional plugins or themes on the affected site enable exploitation of Object Injection vulnerabilities.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.