WordPress BuddyPress before version 7.2.1 is susceptible to a privilege escalation vulnerability that can be leveraged to perform remote code execution.
View the template here CVE-2021-21389.yaml
References:
https://github.com/HoangKien1020/CVE-2021-21389