Access violation vulnerability in CRM WordPress Plugin – RepairBuddy 3.8120

The CRM WordPress Plugin, called RepairBuddy, has a security issue that could allow someone to gain higher levels of access to the plugin. This vulnerability exists in all versions up to 3.8120. The problem lies in the plugin not properly checking a user’s identity before allowing them to update their email using the wc_update_user_data feature. This means that someone with subscriber-level access or higher could change anyone’s email address, even administrators, and use that to reset their password and gain control of their account.

Detected in:

CRM WordPress Plugin – RepairBuddy fixed vulnerable versions: >= * <= 3.8120

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.