CVE-2025-62022: WordPress BuddyPress plugin <= 14.3.4 - Broken Access Control vulnerability
Published Oct 22, 2025
·Updated
Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.
Affected Software
2 affected components
BuddyPress BuddyPress<=14.3.4
WordPress BuddyPress<=14.3.4
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What are the consequences of CVE-2025-62022?
CVE-2025-62022 can lead to unauthorized access to user data and potentially allow attackers to perform actions on behalf of other users.
2
How do I fix CVE-2025-62022?
To fix CVE-2025-62022, update BuddyPress to version 14.3.5 or later.
3
Which versions of BuddyPress are affected by CVE-2025-62022?
CVE-2025-62022 affects BuddyPress versions up to and including 14.3.4.
4
What type of vulnerability is CVE-2025-62022?
CVE-2025-62022 is classified as a Missing Authorization vulnerability.
5
What should I do if I can't update BuddyPress due to compatibility issues related to CVE-2025-62022?
If you can't update BuddyPress, consider implementing access controls or security plugins to mitigate the risk associated with CVE-2025-62022.