Access violation vulnerability in BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages 3.4.19

The BuddyPress WooCommerce My Account Integration plugin for WordPress is at risk of having its data changed without permission. This is because the function wc4bp_shop_profile_sync_ajax() in versions 3.4.19 and below does not have a check for the appropriate permissions. As a result, attackers who are logged in with subscriber-level access or higher can synchronize shop profiles without authorization.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.