Version 12.4.1
Version 12.4.1 is a BuddyPress security release. It was released on May 1, 2024. 1 vulnerability was fixed.
For Version 12.4.1, the database version (_bp_db_version in wp_options) was 13422, and the Trac revision was 13829.
Security fix
- The dynamic Members, dynamic Friends & dynamic Groups blocks were vulnerable to a Stored Cross-Site Scripting. Discovered by Wesley (wcraft) from the Wordfence organization.