CVE-2023-51477

CRITICAL EXPLOITED

BuddyBoss Theme <2.4.60 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-51477 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.

Scores

CVSS v3 9.8
EPSS 0.0070
EPSS Percentile 48.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2023-12-23
CWE
CWE-287
Status published
Products (1)
BUDDYBOSS DMCC/BuddyBoss Theme < 2.4.60
Published Apr 24, 2024
Tracked Since Feb 18, 2026