Description
WordPress Plugin BuddyPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently add a style attributes to "span" and "p" elements in possible rich text fields of their profile page. WordPress Plugin BuddyPress version 6.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.4.0 or latest
References
Related Vulnerabilities
Oracle HTTP Server Improper Certificate Validation Vulnerability (CVE-2020-26184)
WordPress Plugin Advanced Classifieds & Directory Pro Unspecified Vulnerability (1.6.5)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Information Disclosure (9.7.1)
WordPress Plugin Social Essentials-Social Stats and Sharing Buttons Cross-Site Scripting (1.3.1)