Description
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify reviews and plugin settings on the website. WordPress Plugin Wbcom Designs-BuddyPress Group Reviews version 2.8.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8.4 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2108
https://plugins.svn.wordpress.org/review-buddypress-groups/trunk/readme.txt
Related Vulnerabilities
Drupal Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2020-36193)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.16)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5293)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-26267)
WordPress Plugin HyperComments Arbitrary File Deletion (1.2.2)