CVE-2026-59514

WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.


We have discovered 2,827 live websites that are affected by CVE-2026-59514.

Run a Free Instant Scan




Affected Software

Product  BuddyBoss Platform
Category Wordpress Plugins
Vulnerable Domains2,827 live websites (99% of BuddyBoss Platform install base)
Vulnerable Versions
  • from 0 through 3.0.5
Vulnerable Versions Count168 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • VDsec | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-59514
United States1,463 websites



Germany228 websites
France124 websites
GB110 websites
Netherlands93 websites
Cyprus84 websites
Canada64 websites
Australia57 websites
Brazil38 websites
Russia38 websites

Website Distribution by TLD

Number of websites using CVE-2026-59514
.com1,411 websites
.org364 websites
.de83 websites
.nl78 websites
.net75 websites
.fr40 websites
.com.au36 websites
.it35 websites
.com.br33 websites
.co.uk28 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59514

Top websites that are affected by CVE-2026-59514. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
***********.org United States**,***
***********.net United States**,***
**********.com United States**,***
*****.**.il Israel**,***
***********.org United States**,***
**************.com United States**,***
*******************.id Indonesia**,***
****.org United States**,***
*************.com United States**,***
See full domain list

FAQ

CVE-2026-59514 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in BuddyBoss Platform
A total of 2,827 websites have been identified as vulnerable to CVE-2026-59514, based on global website indexing conducted by WebTechSurvey.
The BuddyBoss Platform is affected by the CVE-2026-59514 vulnerability.
BuddyBoss Platform versions up to and including 3.0.5 are vulnerable to CVE-2026-59514.