Description
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify reviews and plugin settings on the website. WordPress Plugin Wbcom Designs-BuddyPress Group Reviews version 2.8.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8.4 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2108
https://plugins.svn.wordpress.org/review-buddypress-groups/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin YARPP-Yet Another Related Posts PHP Object Injection (4.4)
PHP-Fusion URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-23182)
WordPress Plugin Book appointment online Cross-Site Scripting (1.38)
XWiki Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2022-23619)