Access violation vulnerability in BuddyPress Members Only 3.3.5

A security issue has been found in the BuddyPress Members Only plugin for WordPress. This vulnerability affects all versions up to 3.3.5 and allows hackers to access restricted pages and posts through the plugin’s REST API, even if the “All Other Sections On Your Site Will be Opened to Guest” feature is not activated.

Detected in:

BuddyPress Members Only fixed vulnerable versions: >= * <= 3.4.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.