CVE-2025-30957: WordPress Activity Plus Reloaded for BuddyPress <= 1.1.2 - Broken Access Control Vulnerability

5.4 CVSS

Description

Missing Authorization vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Activity Plus Reloaded for BuddyPress: from n/a through 1.1.2.

Classification

CVE ID: CVE-2025-30957

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.4

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem Types

CWE-862 Missing Authorization

Affected Products

Vendor: BuddyDev

Product: Activity Plus Reloaded for BuddyPress

References

https://nvd.nist.gov/vuln/detail/CVE-2025-30957
https://patchstack.com/database/wordpress/plugin/bp-activity-plus-reloaded/vulnerability/wordpress-activity-plus-reloaded-for-buddypress-1-1-2-broken-access-control-vulnerability?_s_id=cve

Timeline