PatchSiren

buddydev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH buddydev CVE published 2026-01-06

CVE-2025-14997

The BuddyPress Xprofile Custom Field Types plugin for WordPress has a vulnerability allowing arbitrary file deletion due to insufficient file path validation in the 'delete_field' function up to version 1.2.8. Authenticated attackers with Subscriber-level access can delete arbitrary files, potentially leading to remote code execution. This vulnerability has a high severity level and requires immediate att [truncated]