PT-2026-66355 · Buddypress+1 · Buddypress
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BuddyPress versions prior to 14.5.1
Description
Authenticated attackers with subscriber-level access and above can inject arbitrary PHP objects via XProfile textbox fields. This occurs because the
bp unserialize profile field() function uses @unserialize() without the allowed classes parameter on user-controlled XProfile field data. This flaw may lead to remote code execution if a suitable POP chain (a sequence of gadgets used to execute arbitrary code during deserialization) is available in the WordPress environment.Recommendations
Update BuddyPress to version 14.5.1 or later.
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buddypress