Access violation vulnerability in BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages 3.4.25

The BuddyPress WooCommerce My Account Integration plugin for WordPress allows users to create WooCommerce Member Pages. However, it has a vulnerability that could allow unauthorized access. This is because it lacks a check for capabilities on the wc4bp_delete_page() function. This vulnerability exists in all versions up to and including 3.4.25. As a result, attackers who are logged in and have Subscriber-level access or higher can make changes to the plugin’s page setting.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.