CVE-2018-25308: Donmik Buddypress Xprofile Custom Fields Type
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server.
Affected products
- Donmik Buddypress Xprofile Custom Fields Type: version 2.6.3 only
Published 2026-04-29. Last modified 2026-06-17.