CVE-2025-62949: WordPress Activity Plus Reloaded for BuddyPress plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Stored XSS.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62949?
CVE-2025-62949 is classified as a Cross-site Scripting (XSS) vulnerability with a significant risk for stored XSS attacks.
How do I fix CVE-2025-62949?
To fix CVE-2025-62949, update Activity Plus Reloaded for BuddyPress to a version later than 1.1.2.
What versions of Activity Plus Reloaded are affected by CVE-2025-62949?
CVE-2025-62949 affects Activity Plus Reloaded for BuddyPress versions up to and including 1.1.2.
What is the impact of CVE-2025-62949?
CVE-2025-62949 can allow attackers to inject malicious scripts that execute in the context of users' web browsers, leading to data theft or account compromise.
Where can I find more information about CVE-2025-62949?
Details about CVE-2025-62949 can typically be found in cybersecurity vulnerability databases or vendor advisories.