In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| buddypress/buddypress(Packagist) | 0 | 5.1.2 | N/A |
CVSS Metrics