Access violation vulnerability in BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages 3.4.24

The BuddyPress WooCommerce My Account Integration plugin for WordPress, which helps create member pages for WooCommerce, has a security vulnerability. This is because it does not check for the appropriate capabilities when using the wc4bp_delete_page() function. This means that attackers who are logged in with Subscriber-level access or higher can potentially change the plugin’s page settings without authorization.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.