CVE-2024-12767: Buddyboss Platform
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts
Affected products
- Buddyboss Buddyboss Platform: before 2.7.60 (fixed in 2.7.60)
Published 2025-05-15. Last modified 2026-06-17.