CVE-2015-9455
Published Oct 7, 2019The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove…
Vendor/product archive
1 CVEs tagged to incsub / buddypress-activity-plus — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove…