📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h Global vulnerability Higher Education CRITICAL 7h Global data_breach Government HIGH 8h Global supply_chain Software Development and Open Source Communities CRITICAL 8h Global malware Software Development CRITICAL 8h Global phishing Multiple Sectors HIGH 9h Global vulnerability Web Applications CRITICAL 9h Global apt Critical Infrastructure CRITICAL 9h Global ransomware Multiple sectors CRITICAL 10h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 10h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 11h
Vulnerabilities

CVE-2024-11976

High
The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action tha
CWE-94 — Weakness Type
Published: Jan 23, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.3
🔗 NVD Official
📄 Description (English)

The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

🤖 AI Executive Summary

CVE-2024-11976 is a critical vulnerability in BuddyPress WordPress plugin (versions ≤14.3.3) allowing unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability enables remote code execution and data manipulation without authentication. Organizations using BuddyPress for community platforms, employee portals, or customer engagement face immediate risk of compromise.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 5, 2026 05:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations heavily impacted include: Banking sector (SAMA-regulated banks using BuddyPress for customer portals), Government agencies (NCA oversight) using community platforms, Healthcare institutions (MOH) with patient engagement portals, Telecommunications (STC, Mobily) with customer communities, and Educational institutions. The vulnerability allows attackers to execute arbitrary WordPress functions, potentially leading to data exfiltration, malware injection, and system compromise. Critical for organizations hosting sensitive citizen/customer data.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Institutions Telecommunications Education Energy and Utilities Retail and E-commerce
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all WordPress installations using BuddyPress plugin via vulnerability scanning
2. Disable BuddyPress plugin immediately if not critical to operations
3. Restrict access to affected WordPress sites via WAF rules blocking suspicious shortcode patterns

PATCHING:
1. Update BuddyPress to version 14.3.4 or later immediately
2. Apply WordPress core updates and all dependent plugins
3. Verify patch installation: check plugin version in WordPress admin dashboard

COMPENSATING CONTROLS (if immediate patching impossible):
1. Implement Web Application Firewall (WAF) rules to block do_shortcode execution patterns
2. Disable user registration and community features temporarily
3. Implement IP whitelisting for administrative access
4. Enable WordPress security plugins with shortcode execution monitoring

DETECTION:
1. Monitor WordPress logs for unusual shortcode patterns: [wp_*, [execute, [system
2. Check database for suspicious post/page content containing shortcodes
3. Review user activity logs for unauthenticated shortcode execution attempts
4. Alert on any do_shortcode function calls from non-authenticated sources
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تثبيتات WordPress التي تستخدم إضافة BuddyPress عبر فحص الثغرات
2. تعطيل إضافة BuddyPress فوراً إذا لم تكن حرجة للعمليات
3. تقييد الوصول إلى مواقع WordPress المتأثرة عبر قواعد WAF لحجب أنماط الاختصارات المريبة

التصحيح:
1. تحديث BuddyPress إلى الإصدار 14.3.4 أو أحدث فوراً
2. تطبيق تحديثات WordPress الأساسية وجميع الإضافات التابعة
3. التحقق من تثبيت التصحيح: تحقق من إصدار الإضافة في لوحة تحكم WordPress

الضوابط البديلة (إذا كان التصحيح الفوري مستحيلاً):
1. تنفيذ قواعد جدار الحماية (WAF) لحجب أنماط تنفيذ do_shortcode
2. تعطيل تسجيل المستخدمين وميزات المجتمع مؤقتاً
3. تنفيذ قائمة بيضاء للعناوين IP للوصول الإداري
4. تفعيل إضافات أمان WordPress مع مراقبة تنفيذ الاختصارات

الكشف:
1. مراقبة سجلات WordPress للأنماط المريبة للاختصارات: [wp_*, [execute, [system
2. فحص قاعدة البيانات للمحتوى المريب في المنشورات/الصفحات التي تحتوي على اختصارات
3. مراجعة سجلات نشاط المستخدم لمحاولات تنفيذ اختصارات غير مصرح بها
4. التنبيه على أي استدعاءات دالة do_shortcode من مصادر غير مصرح بها
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of access
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Asset management SAMA CSF PR.DS-6 - Data security and integrity SAMA CSF DE.CM-1 - Detection processes and tools
🟡 ISO 27001:2022
ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development and change management ISO 27001:2022 A.8.1.1 - User endpoint devices
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
7.3
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity High
CVSS Score7.3
CWECWE-94
EPSS0.10%
Exploit No
Patch ✓ Yes
Published 2026-01-23
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-94
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.