Description
WordPress Plugin BuddyPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a style attributes to "span" and "p" elements in possible rich text fields of their profile page. WordPress Plugin BuddyPress version 6.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.4.0 or latest
References
Related Vulnerabilities
WordPress Plugin RoyalSlider Cross-Site Scripting (3.2.6)
WordPress Plugin Frontend File Manager Arbitrary File Upload (3.7)
Oracle Database Server CVE-2006-3703 Vulnerability (CVE-2006-3703)
WordPress Plugin WP Maintenance Mode & Site Under Construction Cross-Site Request Forgery (1.8.2)
Nginx Improper Certificate Validation Vulnerability (CVE-2009-3555)