Export limit exceeded: 378445 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 378445 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 378445 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-32493 2 Vibethemes, Wordpress 2 Bp Social Connect, Wordpress 2026-04-23 5.9 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect bp-social-connect allows Stored XSS.This issue affects BP Social Connect: from n/a through <= 1.6.2.
CVE-2023-2704 1 Vibethemes 1 Bp Social Connect 2026-04-08 9.8 Critical
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.