
Activity Plus Reloaded for BuddyPress Security & Risk Analysis
wordpress.org/plugins/bp-activity-plus-reloadedNote: This plugin will be discontinued by March 31st, 2025 in favor of BuddyPress Attachment plugin. Please migrate to the new plugin before that date …
Is Activity Plus Reloaded for BuddyPress Safe to Use in 2026?
High Risk
Score 46/100Activity Plus Reloaded for BuddyPress carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The 'bp-activity-plus-reloaded' plugin v1.1.2 exhibits a concerning security posture, primarily due to its significant number of unprotected AJAX handlers and a history of unpatched vulnerabilities. While the plugin demonstrates good practices in using prepared statements for SQL queries and includes some nonce and capability checks, these strengths are overshadowed by critical weaknesses. The static analysis reveals 6 AJAX handlers, all of which lack authentication checks, creating a large attack surface accessible to unauthenticated users. Furthermore, the taint analysis indicates flows with unsanitized paths, suggesting potential for vulnerabilities. The plugin's vulnerability history is particularly worrying, with 3 known CVEs, 2 of which remain unpatched. These past vulnerabilities have included Cross-site Scripting (XSS), Missing Authorization, and Server-Side Request Forgery (SSRF), indicating a pattern of recurring security flaws. The recent nature of the last vulnerability (2025-10-12) is also a red flag, suggesting ongoing development or persistent issues.
In conclusion, while the plugin utilizes prepared statements and some security checks, the prevalence of unprotected entry points and the history of unpatched vulnerabilities, including critical types, make this plugin a high-risk component. The unpatched vulnerabilities and missing authorization checks on AJAX handlers are the most significant concerns, demanding immediate attention. Users should exercise extreme caution and consider disabling or replacing this plugin until these issues are fully addressed.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVEs (2 instances)
- Flows with unsanitized paths
- Output escaping only 52% proper
- Only 1 nonce check
- Only 1 capability check
Activity Plus Reloaded for BuddyPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Activity Plus Reloaded for BuddyPress <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Activity Plus Reloaded for BuddyPress <= 1.1.2 - Missing Authorization
Activity Plus Reloaded for BuddyPress <= 1.1.1 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
Activity Plus Reloaded for BuddyPress Code Analysis
Output Escaping
Data Flow Analysis
Activity Plus Reloaded for BuddyPress Attack Surface
AJAX Handlers 6
Shortcodes 3
WordPress Hooks 11
Maintenance & Trust
Activity Plus Reloaded for BuddyPress Maintenance & Trust
Maintenance Signals
Community Trust
Activity Plus Reloaded for BuddyPress Alternatives
Buddypress Activity Plus Styling
bp-activity-plus-styling
Additional CSS styles for the Buddypress Activity Plus plugin.
Buddypress Jquery Activity Stream Widget
buddypress-jquery-activity-stream-widget
Let your site viewers/users easily read the activity streams by adding a simple yet customizable widget that displays streams in an animated manner.
BuddyPress Activity Shortcode
bp-activity-shortcode
BuddyPress Activity shortcode plugin allows you to insert BuddyPress activity stream on any page/post using shortcode.
BuddyPress Activity Filter
bp-activity-filter
Easily manage your BuddyPress Activity Stream by filtering specific activity types, setting default filters, and enabling public Custom Post Types (CP …
BuddyPress Sitewide Activity Widget
buddypress-sitewide-activity-widget
BuddyPress Sitewide Activity Widget allows you to use BuddyPress Sitewide activity stream as a widget.
Activity Plus Reloaded for BuddyPress Developer Profile
14 plugins · 16K total installs
How We Detect Activity Plus Reloaded for BuddyPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bp-activity-plus-reloaded/assets/css/admin.css/wp-content/plugins/bp-activity-plus-reloaded/assets/js/activity-plus.js/wp-content/plugins/bp-activity-plus-reloaded/assets/js/activity-plus.jsbp-activity-plus-reloaded/assets/css/admin.css?ver=bp-activity-plus-reloaded/assets/js/activity-plus.js?ver=HTML / DOM Fingerprints
bpapr-activity-updatedata-bp-activity-plus-reloadedBPAPR_ACTIVITY_PLUS_RELOADED_PARAMS