CVE-2025-1909
Last modified
CVE-2025-1909 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Buddyboss | Buddyboss Platform | < 2.7.10 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1909?
How severe is CVE-2025-1909?
How do I fix CVE-2025-1909?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1903A vulnerability was found in Codezips Online Shopping Websit…9.8
- CVE-2025-1904A vulnerability, which was classified as problematic, has be…6.1
- CVE-2025-1905A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2025-1906A vulnerability has been found in PHPGurukul Restaurant Tabl…9.8
- CVE-2025-1907Instantel Micromate lacks authentication on a configuration …9.8
- CVE-2025-1908An issue has been discovered in GitLab EE/CE that could allo…7.7
- CVE-2025-1910The WatchGuard Mobile VPN with SSL Client on Windows allows …6.3
- CVE-2025-1911The Product Import Export for WooCommerce – Import Export Pr…6.5
- CVE-2025-1912The Product Import Export for WooCommerce – Import Export Pr…7.6
- CVE-2025-1913The Product Import Export for WooCommerce – Import Export Pr…7.2
- CVE-2025-1914Out of bounds read in V8 in Google Chrome prior to 134.0.699…8.8
- CVE-2025-1915Improper Limitation of a Pathname to a Restricted Directory …8.1
Are you affected by CVE-2025-1909?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
