What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ElbowRobo Mass Messaging in BuddyPress mass-messaging-in-buddypress allows Reflected XSS.This issue affects Mass Messaging in BuddyPress: from n/a through <= 2.2.1.
Explanation of Vulnerability in Simple Terms
02Summary
Mass Messaging in BuddyPress versions 2.2.1 and earlier contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into messages that execute in other users' browsers when they view the message. The vulnerability requires user interaction—the victim must visit a page containing the malicious message. Impact is limited to the BuddyPress messaging component.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in other users' browsers when they view messages.
Potential impact on your site
04Site Impact
Users' session cookies or account data could be stolen if they view a malicious message in BuddyPress.
Conditions required to exploit
05Prerequisites
No authentication required. Victim must visit a page displaying the attacker's message.
Key dates
06Disclosure timeline
January 22, 2025
CVE published
May 11, 2026
Record updated