WordPress Plugin Vulnerabilities

BuddyPress < 6.4.0 - Lack of Capability Check on Profile Page

Description

The 6.4.0 release addresses one security issue: non-capable users could add a style attributes to "span" and "p" elements in possible rich text fields of their profile page. The vulnerability has been fixed.

Affects Plugins

Fixed in 6.4.0

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Timeline

Publicly Published
2020-11-28 (about 5 years ago)
Added
2020-11-28 (about 5 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other