Skip to main content

Vendor/product archive

incsub / buddypress-activity-plus CVEs

Beta · best-effort

1 CVEs tagged to incsub / buddypress-activity-plus0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2015-9455

Published Oct 7, 2019

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1