CVE Database /
CVE-2026-56032
CVE · Critical
CVE-2026-56032 — Buddyboss Platform [buddyboss-platform] < 3.0.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-56032
|
Buddyboss Platform [buddyboss-platform] < 3.0.5 |
Deserialization of Untrusted Data |
Critical
9.8
|
< 3.0.5
|
3.0.5 |
2026-06-23 |
—
|
CVE-2026-56032
Authenticated users with subscriber-level access and above can inject malicious PHP objects into the BuddyBoss Platform plugin for WordPress through versions 3.0.4 and below by exploiting a deserialization vulnerability in untrusted input. This weakness allows potential attackers to introduce arbitrary PHP functionality, which could be leveraged further if additional plugins or themes on the affected site enable exploitation of Object Injection vulnerabilities.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings