The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Sat, 24 May 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Buddyboss
Buddyboss buddyboss Platform |
|
| CPEs | cpe:2.3:a:buddyboss:buddyboss_platform:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Buddyboss
Buddyboss buddyboss Platform |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter in all versions up to, and including, 2.7.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | BuddyBoss Platform <= 2.7.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link_title' | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-27T12:47:01.149Z
Updated: 2025-02-27T14:19:55.288Z
Reserved: 2025-01-14T21:16:08.823Z
Link: CVE-2024-13402
Updated: 2025-02-27T14:19:48.273Z
Status : Analyzed
Published: 2025-02-27T13:15:09.947
Modified: 2025-05-24T01:24:50.903
Link: CVE-2024-13402
No data.