PLUGIN SECURITY
Is Buddypress safe?
Get together safely, in your own way, in WordPress.
What this plugin does
- Slug:
buddypress - Author: BuddyPress
- 90000+ active installs
- 82/100 rating (375 reviews on wordpress.org)
- 13891854 all-time downloads
- On WordPress.org since 2009-04-23
communitygroupmembersnetworkself hosted
Maintenance status
- Latest known version: 14.5.2
- Last updated: 2026-07-29 6:58pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 5.6+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
17 known CVEs on file for Buddypress. Reported between 2011 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-8155 | BuddyPress [buddypress] < 14.5.0 | Authorization Bypass Through User-Controlled Key | Unknown | < 14.5.0 | 14.5.0 | 2026-07-31 | ✓ fixed in latest |
| CVE-2026-53675 | BuddyPress [buddypress] <= 14.4.0 (unfixed) | — | Medium 4.3 | < 14.4.0 | 14.4.0 | 2026-06-09 | ✓ fixed in latest |
| CVE-2026-53674 | BuddyPress [buddypress] <= 14.4.0 (unfixed) | — | High 7.1 | < 14.4.0 | 14.4.0 | 2026-06-09 | ✓ fixed in latest |
| CVE-2026-53673 | BuddyPress [buddypress] <= 14.4.0 (unfixed) | — | High 8.1 | < 14.4.0 | 14.4.0 | 2026-06-09 | ✓ fixed in latest |
| CVE-2020-37233 | BuddyPress [buddypress] <= 6.2.0 (unfixed) | — | Medium 6.4 | < 6.2.0 | 6.2.0 | 2026-05-16 | ✓ fixed in latest |
| CVE-2024-11976 | BuddyPress [buddypress] < 14.3.4 | Improper Control of Generation of Code ('Code Injection') | High 7.3 | < 14.3.4 | 14.3.4 | 2026-01-22 | ✓ fixed in latest |
| CVE-2026-1360 | BuddyPress [buddypress] <= 14.5.0 (unfixed) | Deserialization of Untrusted Data | High 7.5 | < 14.5.0 | 14.5.0 | 2026-01-22 | ✓ fixed in latest |
| CVE-2025-62022 | BuddyPress [buddypress] < 14.4.0 | Missing Authorization | High 7.5 | < 14.4.0 | 14.4.0 | 2025-09-27 | ✓ fixed in latest |
+ 51 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-10011 | BuddyPress [buddypress] < 14.2.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.1 | < 14.2.1 | 14.2.1 | 2024-10-24 | ✓ fixed in latest |
| CVE-2024-4892 | BuddyPress [buddypress] < 12.5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 12.5.1 | 12.5.1 | 2024-06-11 | ✓ fixed in latest |
| CVE-2024-3974 | BuddyPress [buddypress] < 12.4.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 12.4.1 | 12.4.1 | 2024-05-03 | ✓ fixed in latest |
| CVE-2023-50880 | BuddyPress [buddypress] < 11.3.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 11.3.2 | 11.3.2 | 2023-12-26 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 9.1.1 | — | Unknown | < 9.1.1 | 9.1.1 | 2021-08-18 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 9.1.1 | — | Unknown | < 9.1.1 | 9.1.1 | 2021-08-18 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.3.0 | — | Unknown | < 7.3.0 | 7.3.0 | 2021-04-14 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.3.0 | — | Unknown | < 7.3.0 | 7.3.0 | 2021-04-14 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.3.0 | — | Unknown | < 7.3.0 | 7.3.0 | 2021-04-14 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.3.0 | — | Unknown | < 7.3.0 | 7.3.0 | 2021-04-14 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.2.1 | — | Unknown | < 7.2.1 | 7.2.1 | 2021-03-17 | ✓ fixed in latest |
| CVE-2021-21389 | BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0 | Incorrect Authorization | High 8.8 | 5.0.0–7.2.1 | 7.2.1 | 2021-03-16 | ✓ fixed in latest |
| — | BuddyPress [buddypress] >= 7.0.0 - <= 7.2.0 | — | Unknown | 7.0.0–7.2.0 | 7.2.0 | 2021-03-16 | ✓ fixed in latest |
| — | BuddyPress [buddypress] >= 5.0.0 - <= 7.2.0 | — | Unknown | 5.0.0–7.2.0 | 7.2.0 | 2021-03-07 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 6.4.0 | — | Unknown | < 6.4.0 | 6.4.0 | 2020-11-29 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 6.4.0 | — | Unknown | < 6.4.0 | 6.4.0 | 2020-11-27 | ✓ fixed in latest |
| CVE-2020-5244 | BuddyPress [buddypress] < 5.1.2 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 5.1.2 | 5.1.2 | 2020-01-02 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 5.1.1 | — | Unknown | < 5.1.1 | 5.1.1 | 2019-12-23 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 2.7.4 | — | Unknown | < 2.7.4 | 2.7.4 | 2016-12-23 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 2.7.4 | — | Unknown | < 2.7.4 | 2.7.4 | 2016-12-23 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 2.3.5 | — | Unknown | < 2.3.5 | 2.3.5 | 2015-11-12 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 2.3.5 | — | Unknown | < 2.3.5 | 2.3.5 | 2015-11-11 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 1.7.2 | — | Unknown | < 1.7.2 | 1.7.2 | 2015-05-15 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 1.2.10 | — | Unknown | < 1.2.10 | 1.2.10 | 2015-05-15 | ✓ fixed in latest |
| CVE-2014-1888 | BuddyPress [buddypress] < 1.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 1.9.2 | 1.9.2 | 2014-02-07 | ✓ fixed in latest |
| CVE-2014-1889 | BuddyPress [buddypress] < 1.9.2 | — | Medium 6.5 | < 1.9.2 | 1.9.2 | 2014-02-05 | ✓ fixed in latest |
| CVE-2012-2109 | BuddyPress [buddypress] < 1.5.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Unknown | < 1.5.5 | 1.5.5 | 2012-03-27 | ✓ fixed in latest |
| — | BuddyPress [buddypress] <= 1.2.10 | — | Unknown | < 1.2.10 | 1.2.10 | 2011-09-26 | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 9.1.1 | — | Unknown | < 9.1.1 | 9.1.1 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 9.1.1 | — | Unknown | < 9.1.1 | 9.1.1 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.3.0 | — | Unknown | < 7.3.0 | 7.3.0 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 7.2.1 | — | Unknown | < 7.2.1 | 7.2.1 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 6.4.0 | — | Unknown | < 6.4.0 | 6.4.0 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] >= 5.0.0 - <= 5.1.1 | — | Unknown | 5.0.0–5.1.1 | 5.1.1 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 5.1.1 | — | Unknown | < 5.1.1 | 5.1.1 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] >= 2.0 - <= 2.7.3 | — | Unknown | 2.0–2.7.3 | 2.7.3 | — | ✓ fixed in latest |
| — | BuddyPress [buddypress] < 1.7.2 | — | Unknown | < 1.7.2 | 1.7.2 | — | ✓ fixed in latest |
| — | BuddyPress 1.7.1 - Multiple SQL Injections | — | Unknown | < 1.7.2 | 1.7.2 | — | ✓ fixed in latest |
| — | BuddyPress 1.2.9 - SQL Injection | — | Unknown | < 1.2.10 | 1.2.10 | — | ✓ fixed in latest |
| — | BuddyPress <= 2.3.4 - Authenticated Privilege Escalation | — | Unknown | < 2.3.5 | 2.3.5 | — | ✓ fixed in latest |
| — | BuddyPress 2.0-2.7.3 - Arbitrary File Deletion | — | Unknown | < 2.7.4 | 2.7.4 | — | ✓ fixed in latest |
| — | BuddyPress 5.0.0-5.1.1 - Private Data Exposure via REST API | — | Unknown | < 5.1.2 | 5.1.2 | — | ✓ fixed in latest |
| — | BuddyPress < 5.1.1 - Denial of Service | — | Unknown | < 5.1.1 | 5.1.1 | — | ✓ fixed in latest |
| — | BuddyPress < 6.4.0 - Lack of Capability Check on Profile Page | — | Unknown | < 6.4.0 | 6.4.0 | — | ✓ fixed in latest |
| — | BuddyPress < 7.2.1 - Force a Friendship | — | Unknown | < 7.2.1 | 7.2.1 | — | ✓ fixed in latest |
| — | BuddyPress < 7.2.1 - Read Private Messages | — | Unknown | < 7.2.1 | 7.2.1 | — | ✓ fixed in latest |
| — | BuddyPress < 7.2.1 - Manage BuddyPress Member Types | — | Unknown | < 7.2.1 | 7.2.1 | — | ✓ fixed in latest |
| — | BuddyPress < 7.2.1 - Invite Member to Join Group | — | Unknown | < 7.2.1 | 7.2.1 | — | ✓ fixed in latest |
| — | BuddyPress < 7.3.0 - Multiple Authenticated REST API Vulnerabilities | — | Unknown | < 7.3.0 | 7.3.0 | — | ✓ fixed in latest |
| — | BuddyPress < 9.1.1 - Activation Key Disclosure | — | Unknown | < 9.1.1 | 9.1.1 | — | ✓ fixed in latest |
| — | BuddyPress < 9.1.1 - SQL Injections | — | Unknown | < 9.1.1 | 9.1.1 | — | ✓ fixed in latest |
How to fix it
Keep Buddypress updated — 14.5.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — 200000+ active installs — 88/100 (1444) — max PHP 8.4
- WP Telegram (Auto Post and Notifications) — 30000+ active installs — 100/100 (426) — max PHP <8.0
- Ultimate Member – reCAPTCHA — 20000+ active installs — 74/100 (11) — max PHP 8.4
- wpForo Forum — 20000+ active installs — 94/100 (390)
- Asgaros Forum — 10000+ active installs — 96/100 (208)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.