Description
WordPress Plugin WooCommerce BuddyPress Integration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently perform a variety of the plugin's actions or even take over a website. WordPress Plugin WooCommerce BuddyPress Integration version 3.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6 or latest
References
Related Vulnerabilities
Jenkins Insufficient Session Expiration Vulnerability (CVE-2019-1003004)
MySQL CVE-2024-21134 Vulnerability (CVE-2024-21134)
Mailman Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-42097)
SharePoint CVE-2024-38228 Vulnerability (CVE-2024-38228)
WordPress Plugin User Access Manager Cross-Site Scripting (1.2.14)