HomeDefault status
unaffected
Any version before 2.7.60
affected
Description
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 2.7.60
Credits
Faris Krivić
WPScan
References
wpscan.com/...rability/e8997f90-d8e9-4815-8808-aa0183443dae/