Vulnerability Description
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buddyboss | Buddyboss Platform | < 2.7.60 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e8997f90-d8e9-4815-8808-aa0183443dae/ExploitThird Party Advisory
FAQ
What is CVE-2024-12767?
CVE-2024-12767 is a vulnerability with a CVSS score of 3.5 (LOW). The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
How severe is CVE-2024-12767?
CVE-2024-12767 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-12767?
Check the references section above for vendor advisories and patch information. Affected products include: Buddyboss Buddyboss Platform.