CVE-2012-2109

high
Published 2012-09-04 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://buddypress.org/2012/03/buddypress-1-5-5/

Application impact

VendorProductVersionsFixed
buddypressbuddypress1.5
buddypressbuddypress1.5.1
buddypressbuddypress1.5.2
buddypressbuddypress1.5.3
buddypressbuddypress1.5.3.1
buddypressbuddypress1.5.4
wordpress wordpresswordpress-

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.