PLUGIN SECURITY
Is Buddyboss Platform safe?
Use remote media as the featured image and beyond.
What this plugin does
- Slug:
buddyboss-platform - Author: fifu.app
- 60000+ active installs
- 92/100 rating (264 reviews on wordpress.org)
- 7345332 all-time downloads
- On WordPress.org since 2015-10-03
featuredimageremoteurlwoocommerce
Maintenance status
- Latest known version: 2.15.24
- Last updated: 2026-09-01 4:26pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 8.1+
Known vulnerabilities
9 known CVEs on file for Buddyboss Platform.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-56032 | Buddyboss Platform [buddyboss-platform] < 3.0.5 | Deserialization of Untrusted Data | Critical 9.8 | < 3.0.5 | 3.0.5 | 2026-06-23 | ⚠ update needed |
| CVE-2024-13858 | Buddyboss Platform [buddyboss-platform] < 2.8.51 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.8.51 | 2.8.51 | 2025-05-01 | ✓ fixed in latest |
| CVE-2024-13859 | Buddyboss Platform [buddyboss-platform] < 2.8.51 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.8.51 | 2.8.51 | 2025-05-01 | ✓ fixed in latest |
| CVE-2024-13860 | Buddyboss Platform [buddyboss-platform] < 2.8.51 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.8.51 | 2.8.51 | 2025-05-01 | ✓ fixed in latest |
| CVE-2024-13402 | Buddyboss Platform [buddyboss-platform] < 2.8.00 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.8.00 | 2.8.00 | 2025-02-26 | ✓ fixed in latest |
| CVE-2024-12767 | Buddyboss Platform [buddyboss-platform] < 2.7.60 | Authorization Bypass Through User-Controlled Key | Low 3.5 | < 2.7.60 | 2.7.60 | 2025-01-14 | ✓ fixed in latest |
| CVE-2024-4886 | Buddyboss Platform [buddyboss-platform] < 2.6.0 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 2.6.0 | 2.6.0 | 2024-05-15 | ✓ fixed in latest |
| CVE-2024-4750 | Buddyboss Platform [buddyboss-platform] < 2.6.0 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 2.6.0 | 2.6.0 | 2024-05-14 | ✓ fixed in latest |
+ 6 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Buddyboss Platform [buddyboss-platform] < 1.7.9 | — | Unknown | < 1.7.9 | 1.7.9 | 2021-09-16 | ✓ fixed in latest |
| — | Buddyboss Platform [buddyboss-platform] < 1.7.9 | — | Unknown | < 1.7.9 | 1.7.9 | 2021-09-16 | ✓ fixed in latest |
| — | Buddyboss Platform [buddyboss-platform] < 3.1.0 | — | Unknown | < 3.1.0 | 3.1.0 | 0000-00-00 | ⚠ update needed |
| — | Buddyboss Platform [buddyboss-platform] < 1.7.9 | — | Unknown | < 1.7.9 | 1.7.9 | — | ✓ fixed in latest |
| — | Buddyboss Platform < 1.7.9 - Subscriber+ SQL Injection | — | Unknown | < 1.7.9 | 1.7.9 | — | ✓ fixed in latest |
| CVE-2026-59514 | BuddyBoss Platform < 3.1.0 - Unauthenticated SQL Injection | — | Unknown | < 3.1.0 | 3.1.0 | — | ⚠ update needed |
How to fix it
Keep Buddyboss Platform updated — 2.15.24 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Imsanity — 200000+ active installs — 98/100 (292) — max PHP 8.4
- Firelight Lightbox — 200000+ active installs — 96/100 (357) — max PHP 8.4
- Responsive Lightbox & Gallery — 100000+ active installs — 98/100 (1999) — max PHP 8.4
- Simple Lightbox — 100000+ active installs — 86/100 (239) — max PHP <8.0
- reSmush.it : The original free image compressor and optimizer plugin — 100000+ active installs — 86/100 (165)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.