Vulnerability Description
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Incsub | Buddypress-Activity-Plus | < 1.6.2 |
Related Weaknesses (CWE)
References
- https://security.dxw.com/advisories/csrf-and-arbitrary-file-deletion-in-buddypreThird Party Advisory
- https://wordpress.org/plugins/buddypress-activity-plus/#developersProductRelease Notes
- https://security.dxw.com/advisories/csrf-and-arbitrary-file-deletion-in-buddypreThird Party Advisory
- https://wordpress.org/plugins/buddypress-activity-plus/#developersProductRelease Notes
FAQ
What is CVE-2015-9455?
CVE-2015-9455 is a vulnerability with a CVSS score of 8.1 (HIGH). The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
How severe is CVE-2015-9455?
CVE-2015-9455 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-9455?
Check the references section above for vendor advisories and patch information. Affected products include: Incsub Buddypress-Activity-Plus.