The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
2019-10-07T15:15:10.450
2024-11-21T02:40:40.620
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:C
8.6
7.8
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | incsub | buddypress-activity-plus | < 1.6.2 | Yes |