CVE-2024-12767: Buddyboss Platform

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

Affected products

  • Buddyboss Buddyboss Platform: before 2.7.60 (fixed in 2.7.60)

Published 2025-05-15. Last modified 2026-06-17.