SecAlerts
k

kainelabs

Security Risk Profile

36
/100
low

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 2, 2021 to present

13
Total CVEs
5
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
36/100
low

Severity Distribution

Critical
1
High
4
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
4
2
SQL Injection
3

Most Affected Products

1. KaineLabs Youzify Wordpress13
2. Youzify BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress2
3. KaineLabs Youzify2
4. WordPress Youzify1
5. KaineLabs Youzify - Buddypress Moderation1

Recent Vulnerabilities

See more →
CVE-2024-13370
CVSS 6.5medium

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)

Jan 25, 2025🔧 No Patch
CVE-2024-13368
CVSS 4.3medium

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

Jan 25, 2025🔧 No Patch
CVE-2024-12113
CVSS 4.3medium

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion

Jan 25, 2025🔧 No Patch
CVE-2024-39635
CVSS 8.8high

WordPress Youzify plugin <= 1.2.6 - Broken Access Control vulnerability

Nov 1, 2024
CVE-2024-9067
CVSS 4.3EPSS 0%medium

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion

Oct 10, 2024🔧 No Patch
CVE-2024-8987
CVSS 6.4EPSS 0%medium

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode

Oct 10, 2024🔧 No Patch
CVE-2024-37494
CVSS 8.8high

WordPress Youzify plugin <= 1.2.5 - SQL Injection vulnerability

Jul 9, 2024
CVE-2024-4742
CVSS 8.8EPSS 0%high

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection

Jun 20, 2024🔧 No Patch
CVE-2024-2864
CVSS 7.3EPSS 0%high

WordPress Youzify - Buddypress Moderation plugin <= 1.2.5 - Unauthenticated Cross Site Scripting (XSS) vulnerability

Mar 25, 2024🔧 No Patch
CVE-2023-47191
CVSS 6.5medium

WordPress Youzify Plugin <= 1.2.2 is vulnerable to Insecure Direct Object References (IDOR)

Dec 21, 2023

Monitor kainelabs in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.