BuddyPress 2.3.3 is available and users are encouraged to update as soon as possible. A few security vulnerabilities were discovered in BuddyPress Messages, a core component that allows users to send and receive private messages. A vulnerability was responsibly disclosed to the BuddyPress team that could allow members to manipulate a failed private outbound message and inject unexpected output to the browser.