PLUGIN SECURITY

Is Buddypress safe?

Get together safely, in your own way, in WordPress.

What this plugin does

  • Slug: buddypress
  • Author: BuddyPress
  • 90000+ active installs
  • 82/100 rating (375 reviews on wordpress.org)
  • 13891854 all-time downloads
  • On WordPress.org since 2009-04-23

communitygroupmembersnetworkself hosted

Maintenance status

  • Latest known version: 14.5.2
  • Last updated: 2026-07-29 6:58pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 5.6+
  • Max supported PHP (analyzed): <8.0

Known vulnerabilities

17 known CVEs on file for Buddypress. Reported between 2011 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8155 BuddyPress [buddypress] < 14.5.0 Authorization Bypass Through User-Controlled Key Unknown < 14.5.0 14.5.0 2026-07-31 ✓ fixed in latest
CVE-2026-53675 BuddyPress [buddypress] <= 14.4.0 (unfixed) Medium 4.3 < 14.4.0 14.4.0 2026-06-09 ✓ fixed in latest
CVE-2026-53674 BuddyPress [buddypress] <= 14.4.0 (unfixed) High 7.1 < 14.4.0 14.4.0 2026-06-09 ✓ fixed in latest
CVE-2026-53673 BuddyPress [buddypress] <= 14.4.0 (unfixed) High 8.1 < 14.4.0 14.4.0 2026-06-09 ✓ fixed in latest
CVE-2020-37233 BuddyPress [buddypress] <= 6.2.0 (unfixed) Medium 6.4 < 6.2.0 6.2.0 2026-05-16 ✓ fixed in latest
CVE-2024-11976 BuddyPress [buddypress] < 14.3.4 Improper Control of Generation of Code ('Code Injection') High 7.3 < 14.3.4 14.3.4 2026-01-22 ✓ fixed in latest
CVE-2026-1360 BuddyPress [buddypress] <= 14.5.0 (unfixed) Deserialization of Untrusted Data High 7.5 < 14.5.0 14.5.0 2026-01-22 ✓ fixed in latest
CVE-2025-62022 BuddyPress [buddypress] < 14.4.0 Missing Authorization High 7.5 < 14.4.0 14.4.0 2025-09-27 ✓ fixed in latest
+ 51 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10011 BuddyPress [buddypress] < 14.2.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.1 < 14.2.1 14.2.1 2024-10-24 ✓ fixed in latest
CVE-2024-4892 BuddyPress [buddypress] < 12.5.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 12.5.1 12.5.1 2024-06-11 ✓ fixed in latest
CVE-2024-3974 BuddyPress [buddypress] < 12.4.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 12.4.1 12.4.1 2024-05-03 ✓ fixed in latest
CVE-2023-50880 BuddyPress [buddypress] < 11.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 11.3.2 11.3.2 2023-12-26 ✓ fixed in latest
BuddyPress [buddypress] < 9.1.1 Unknown < 9.1.1 9.1.1 2021-08-18 ✓ fixed in latest
BuddyPress [buddypress] < 9.1.1 Unknown < 9.1.1 9.1.1 2021-08-18 ✓ fixed in latest
BuddyPress [buddypress] < 7.3.0 Unknown < 7.3.0 7.3.0 2021-04-14 ✓ fixed in latest
BuddyPress [buddypress] < 7.3.0 Unknown < 7.3.0 7.3.0 2021-04-14 ✓ fixed in latest
BuddyPress [buddypress] < 7.3.0 Unknown < 7.3.0 7.3.0 2021-04-14 ✓ fixed in latest
BuddyPress [buddypress] < 7.3.0 Unknown < 7.3.0 7.3.0 2021-04-14 ✓ fixed in latest
BuddyPress [buddypress] < 7.2.1 Unknown < 7.2.1 7.2.1 2021-03-17 ✓ fixed in latest
CVE-2021-21389 BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0 Incorrect Authorization High 8.8 5.0.0–7.2.1 7.2.1 2021-03-16 ✓ fixed in latest
BuddyPress [buddypress] >= 7.0.0 - <= 7.2.0 Unknown 7.0.0–7.2.0 7.2.0 2021-03-16 ✓ fixed in latest
BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0 Unknown 5.0.0–7.2.0 7.2.0 2021-03-07 ✓ fixed in latest
BuddyPress [buddypress] < 6.4.0 Unknown < 6.4.0 6.4.0 2020-11-29 ✓ fixed in latest
BuddyPress [buddypress] < 6.4.0 Unknown < 6.4.0 6.4.0 2020-11-27 ✓ fixed in latest
CVE-2020-5244 BuddyPress [buddypress] < 5.1.2 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 5.1.2 5.1.2 2020-01-02 ✓ fixed in latest
BuddyPress [buddypress] < 5.1.1 Unknown < 5.1.1 5.1.1 2019-12-23 ✓ fixed in latest
BuddyPress [buddypress] < 2.7.4 Unknown < 2.7.4 2.7.4 2016-12-23 ✓ fixed in latest
BuddyPress [buddypress] < 2.7.4 Unknown < 2.7.4 2.7.4 2016-12-23 ✓ fixed in latest
BuddyPress [buddypress] < 2.3.5 Unknown < 2.3.5 2.3.5 2015-11-12 ✓ fixed in latest
BuddyPress [buddypress] < 2.3.5 Unknown < 2.3.5 2.3.5 2015-11-11 ✓ fixed in latest
BuddyPress [buddypress] < 1.7.2 Unknown < 1.7.2 1.7.2 2015-05-15 ✓ fixed in latest
BuddyPress [buddypress] < 1.2.10 Unknown < 1.2.10 1.2.10 2015-05-15 ✓ fixed in latest
CVE-2014-1888 BuddyPress [buddypress] < 1.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.9.2 1.9.2 2014-02-07 ✓ fixed in latest
CVE-2014-1889 BuddyPress [buddypress] < 1.9.2 Medium 6.5 < 1.9.2 1.9.2 2014-02-05 ✓ fixed in latest
CVE-2012-2109 BuddyPress [buddypress] < 1.5.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 1.5.5 1.5.5 2012-03-27 ✓ fixed in latest
BuddyPress [buddypress] <= 1.2.10 Unknown < 1.2.10 1.2.10 2011-09-26 ✓ fixed in latest
BuddyPress [buddypress] < 9.1.1 Unknown < 9.1.1 9.1.1 ✓ fixed in latest
BuddyPress [buddypress] < 9.1.1 Unknown < 9.1.1 9.1.1 ✓ fixed in latest
BuddyPress [buddypress] < 7.3.0 Unknown < 7.3.0 7.3.0 ✓ fixed in latest
BuddyPress [buddypress] < 7.2.1 Unknown < 7.2.1 7.2.1 ✓ fixed in latest
BuddyPress [buddypress] < 6.4.0 Unknown < 6.4.0 6.4.0 ✓ fixed in latest
BuddyPress [buddypress] >= 5.0.0 - <= 5.1.1 Unknown 5.0.0–5.1.1 5.1.1 ✓ fixed in latest
BuddyPress [buddypress] < 5.1.1 Unknown < 5.1.1 5.1.1 ✓ fixed in latest
BuddyPress [buddypress] >= 2.0 - <= 2.7.3 Unknown 2.0–2.7.3 2.7.3 ✓ fixed in latest
BuddyPress [buddypress] < 1.7.2 Unknown < 1.7.2 1.7.2 ✓ fixed in latest
BuddyPress 1.7.1 - Multiple SQL Injections Unknown < 1.7.2 1.7.2 ✓ fixed in latest
BuddyPress 1.2.9 - SQL Injection Unknown < 1.2.10 1.2.10 ✓ fixed in latest
BuddyPress <= 2.3.4 - Authenticated Privilege Escalation Unknown < 2.3.5 2.3.5 ✓ fixed in latest
BuddyPress 2.0-2.7.3 - Arbitrary File Deletion Unknown < 2.7.4 2.7.4 ✓ fixed in latest
BuddyPress 5.0.0-5.1.1 - Private Data Exposure via REST API Unknown < 5.1.2 5.1.2 ✓ fixed in latest
BuddyPress < 5.1.1 - Denial of Service Unknown < 5.1.1 5.1.1 ✓ fixed in latest
BuddyPress < 6.4.0 - Lack of Capability Check on Profile Page Unknown < 6.4.0 6.4.0 ✓ fixed in latest
BuddyPress < 7.2.1 - Force a Friendship Unknown < 7.2.1 7.2.1 ✓ fixed in latest
BuddyPress < 7.2.1 - Read Private Messages Unknown < 7.2.1 7.2.1 ✓ fixed in latest
BuddyPress < 7.2.1 - Manage BuddyPress Member Types Unknown < 7.2.1 7.2.1 ✓ fixed in latest
BuddyPress < 7.2.1 - Invite Member to Join Group Unknown < 7.2.1 7.2.1 ✓ fixed in latest
BuddyPress < 7.3.0 - Multiple Authenticated REST API Vulnerabilities Unknown < 7.3.0 7.3.0 ✓ fixed in latest
BuddyPress < 9.1.1 - Activation Key Disclosure Unknown < 9.1.1 9.1.1 ✓ fixed in latest
BuddyPress < 9.1.1 - SQL Injections Unknown < 9.1.1 9.1.1 ✓ fixed in latest

How to fix it

Keep Buddypress updated — 14.5.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.