CVE-2020-5244: Private data exposure via REST API in BuddyPress
Published Feb 24, 2020
·Updated
In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
Affected Software
1 affected component
BuddyPress Buddypress Wordpress>=5.0.0<5.1.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BuddyPressto a version that resolves this vulnerability.Fixed in 5.1.2
Event History
Feb 24, 2020
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-5244?
CVE-2020-5244 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2020-5244?
To fix CVE-2020-5244, update BuddyPress to version 5.1.2 or later.
3
What does CVE-2020-5244 affect?
CVE-2020-5244 affects BuddyPress versions prior to 5.1.2.
4
What type of data is exposed in CVE-2020-5244?
CVE-2020-5244 can expose private user data through a certain REST API endpoint.
5
Is authentication required to exploit CVE-2020-5244?
No, CVE-2020-5244 can be exploited without any authentication.