Executive brief
The Buddyboss Platform, a popular WordPress plugin used to build online communities and social networks, contains a critical security flaw. An unauthenticated attacker can remotely access and manipulate the website's database without needing a password. This could lead to the theft of sensitive user information, exposure of private community data, or disruption of site operations.
Technical details
A SQL injection vulnerability exists in the Buddyboss Platform plugin (<= 3.0.5) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the server to execute arbitrary SQL queries. Successful exploitation can lead to unauthorized data exfiltration from the WordPress database or limited impact on availability. The vulnerability is addressed in version 3.1.0.
Affected products
- BuddyBoss Buddyboss Platform <= 3.0.5
Timeline
- 2026-06-26: other: Reported by VDsec
- 2026-07-09: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD