CVE-2024-13858: BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name'
The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inviteename’ parameter in all versions up to, and including, 2.8.50 and 2.8.41, respectively, due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in the BuddyBoss Platform plugin in version 2.8.41.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13858?
CVE-2024-13858 has been classified as a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13858?
To fix CVE-2024-13858, update the Buddyboss Platform plugin to version 2.8.51 or later where the vulnerability has been patched.
Who is affected by CVE-2024-13858?
CVE-2024-13858 affects users of the Buddyboss Platform plugin for WordPress on all versions up to and including 2.8.50.
What type of attack is associated with CVE-2024-13858?
CVE-2024-13858 is associated with Stored Cross-Site Scripting attacks due to insufficient input sanitization.
Can unauthenticated users exploit CVE-2024-13858?
No, only authenticated users with appropriate privileges can exploit CVE-2024-13858.