Skip to:
Content
Pages
Categories
Search
Top
Bottom

Unauthenticated Arbitrary Shortcode Execution Security Vulnerability

  • @pineapplepalm

    Participant

    Wordpress announced a Buddypress security vulnerability some hours ago, which appears to be unpatched. Can you please advise when this will be addressed?

    Thanks to the team

Viewing 4 replies - 1 through 4 (of 4 total)
  • @emaralive

    Moderator

    Wordfence posted this alert on January 22, 2026, which can be found here. Similarly, Patchstack had reported the alert on January 23, 2026, which can be found here.

    In either case, both sites indicate that this was patched in BuddyPress version 14.3.4, which the release was announced in March of 2025, approximately 10 months ago. See the following:

    Additionally, in the future, you may want to consider refraining from double posting.

    @pineapplepalm

    Participant

    Thanks for the response. That makes sense why the status seemed unusual.

    Are you aware why this would be so recently reported and accepted as a current threat, if it was already resolved 10 months back? Odd for sure.

    Thanks for any clarity.

    *feel free to delete the other comment if you so wish.

    @emaralive

    Moderator

    You would have to ask the researcher who submitted the CVE or the indicated authoritative bodies as to why.

    @mike80222

    Participant

    @pineapplepalm, The reason it wasn’t posted until now was because when serious vulnerabilities are found the announcements are held back until patches can be released, and people have already had time to update their sites. Otherwise you’d be announcing the vulnerabilities to hackers before the fixes had been distributed.

Viewing 4 replies - 1 through 4 (of 4 total)
  • You must be logged in to reply to this topic.
Skip to toolbar