CVE-2024-12767: BuddyBoss platform < 2.7.60 - Private Comment Exposure via IDOR
Published May 15, 2025
·Updated
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
Affected Software
2 affected components
Buddyboss BuddyBoss Platform<2.7.60
Buddyboss Buddyboss Platform Wordpress<2.7.60
Event History
May 15, 2025
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12767?
CVE-2024-12767 has a medium severity rating due to improper access controls that expose private comments.
2
How do I fix CVE-2024-12767?
To fix CVE-2024-12767, update the BuddyBoss Platform plugin to version 2.7.60 or later.
3
Who is affected by CVE-2024-12767?
Any user of the BuddyBoss Platform plugin version prior to 2.7.60 is affected by CVE-2024-12767.
4
What are the consequences of CVE-2024-12767?
The consequence of CVE-2024-12767 is that logged-in users can view comments on private posts, potentially exposing sensitive content.
5
When was CVE-2024-12767 reported?
CVE-2024-12767 was reported in 2024 and pertains to versions of the BuddyBoss Platform before 2.7.60.