First published: Mon Jan 27 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress BuddyPress Groups Extras | <=3.6.10 | |
BuddyPress Groups Extras | <=3.6.10 |
Update the WordPress BuddyPress Groups Extras wordpress plugin to the latest available version (at least 3.7.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24538 is considered a high severity Cross-Site Request Forgery (CSRF) vulnerability affecting specific versions of BuddyPress Groups Extras.
To fix CVE-2025-24538, update the BuddyPress Groups Extras plugin to version 3.6.11 or later.
CVE-2025-24538 affects BuddyPress Groups Extras versions from n/a through 3.6.10.
CVE-2025-24538 allows attackers to perform unauthorized actions on behalf of authenticated users, potentially compromising the integrity of user accounts.
While specific exploits are not typically disclosed, the nature of a CSRF vulnerability suggests that it can be exploited if the affected versions are not updated.