Description
WordPress Plugin BuddyPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently remove another user's avatar and also any empty folder. WordPress Plugin BuddyPress version 5.1.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP Mail Logging Cross-Site Scripting (1.11.1)
WordPress Plugin Booking Multiple Vulnerabilities (2.5)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)
WordPress Plugin Windows Desktop and iPhone Photo Uploader Arbitrary File Upload (1.8)
Plone CMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-28734)