Version 12.4.1
Version 12.4.1 is a BuddyPress security release. It was released on May 1, 2024. 1 vulnerability was fixed.
For Version 12.4.1, the database version (_bp_db_version
in wp_options
) was 13422
, and the Trac revision was 13829
.
Security fix
- The dynamic Members, dynamic Friends & dynamic Groups blocks were vulnerable to a Stored Cross-Site Scripting. Discovered by Wesley (wcraft) from the Wordfence organization.