Plugin Vulnerability Hub
Plugin 14 known issues Latest disclosed Apr 17, 2026

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Vulnerabilities

Review known vulnerability records for the WordPress plugin Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress (`youzify`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-1559, CVE-2025-69014 and CVE-2024-13370, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
14
High or Critical
2
Patch Coverage
100%
Last Updated
Apr 17, 2026
Priority CVE Quick Links

Fast paths into Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
14
CVE-2024-37494 Critical 1.2.6
CVE-2024-37494 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress SQL Injection

Youzify <= 1.2.5 - Authenticated (Contributor+) SQL Injection

CVE-2022-1950 Critical 1.2.0
CVE-2022-1950 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress SQL Injection

Youzify <= 1.1.9 - SQL Injection

CVE-2024-13370 Medium 1.3.4
CVE-2024-13370 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Vulnerability

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)

CVE-2024-4742 Medium 1.2.6
CVE-2024-4742 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress SQL Injection

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection

CVE-2023-47191 Medium 1.2.3
CVE-2023-47191 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Authorization Bypass

Youzify <= 1.2.2 - Insecure Direct Object Reference

CVE-2026-1559 Medium 1.3.7
CVE-2026-1559 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Stored Cross-Site Scripting

Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter

CVE-2025-69014 Medium No patch listed
CVE-2025-69014 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Server-Side Request Forgery

Youzify <= 1.3.5 - Authenticated (Subscriber+) Server-Side Request Forgery

CVE-2024-8987 Medium 1.3.1
CVE-2024-8987 Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress Stored Cross-Site Scripting

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
14 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 0 high severity findings.
Recent CVEs
CVE-2026-1559, CVE-2025-69014 and CVE-2024-13370
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2024-13370 Medium Patch path listed

CVE-2024-13370: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check...

Published
Jan 24, 2025
Patch Status
1.3.4
Known Vulnerabilities

Reports for Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-1559
CVE-2026-1559: Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subs...

Published
Apr 17, 2026
Patched Release
1.3.7
Affected Versions
Versions up to 1.3.6
Next Step
Update to 1.3.7 or newer if supported.
Plugin Medium Patched: No CVE-2025-69014
CVE-2025-69014: Youzify <= 1.3.5 - Authenticated (Subscriber+) Server-Side Request Forgery

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with Subscriber-le...

Published
Dec 27, 2025
Patched Release
Not published
Affected Versions
Versions up to 1.3.5
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2024-13370
CVE-2024-13370: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license)

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.3. Thi...

Published
Jan 24, 2025
Patched Release
1.3.4
Affected Versions
Versions up to 1.3.3
Next Step
Update to 1.3.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13368
CVE-2024-13368: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4. This...

Published
Jan 24, 2025
Patched Release
1.3.5
Affected Versions
Versions up to 1.3.4
Next Step
Update to 1.3.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12113
CVE-2024-12113: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, an...

Published
Jan 24, 2025
Patched Release
1.3.3
Affected Versions
Versions up to 1.3.2
Next Step
Update to 1.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8987
CVE-2024-8987: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sani...

Published
Oct 09, 2024
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9067
CVE-2024-9067: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1...

Published
Oct 09, 2024
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-39635
CVE-2024-39635: Youzify <= 1.2.6 - Missing Authorization

The Youzify plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized ac...

Published
Jul 24, 2024
Patched Release
1.2.8
Affected Versions
Versions up to 1.2.6
Next Step
Update to 1.2.8 or newer if supported.
Plugin Critical Patched: Yes CVE-2024-37494
CVE-2024-37494: Youzify <= 1.2.5 - Authenticated (Contributor+) SQL Injection

The Youzify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wi...

Published
Jul 04, 2024
Patched Release
1.2.6
Affected Versions
Versions up to 1.2.5
Next Step
Update to 1.2.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4742
CVE-2024-4742: Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplie...

Published
Jun 19, 2024
Patched Release
1.2.6
Affected Versions
Versions up to 1.2.5
Next Step
Update to 1.2.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-47191
CVE-2023-47191: Youzify <= 1.2.2 - Insecure Direct Object Reference

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.2 due to missing validation on a user controlled key. This makes it...

Published
Nov 03, 2023
Patched Release
1.2.3
Affected Versions
Versions up to 1.2.2
Next Step
Update to 1.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0059
CVE-2023-0059: Youzify <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

Published
Jan 24, 2023
Patched Release
1.2.2
Affected Versions
Versions up to 1.2.1
Next Step
Update to 1.2.2 or newer if supported.