---
id: CVE-2020-37233
title: >-
  WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting
  vulnerability that allows authenticated attackers with moderator privileges to
  inject malicious script code through the figure parameter in wp:html blocks
summary: >-
  WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting
  vulnerability that allows authenticated attackers with moderator privileges to
  inject malicious script code through the figure parameter in wp:html blocks.
  Atta…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37233'
references:
  - url: 'https://wordpress.org/plugins/buddypress/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49061'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-plugin-buddypress-persistent-cross-site-scripting
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00278
epssPercentile: 0.18175
ingestedAt: '2026-09-29T10:31:36.284Z'
---

## Overview

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onload that execute when administrators or privileged users preview or view the affected page content, enabling session hijacking and persistent phishing attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
