BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages
cpe:2.3:a:themekraft:buddypress_woocommerce_my_account_integration:*:*:*:*:wordpress:*:*
- <= 3.4.24
A vulnerability exists in the BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress, in versions through 3.4.24. The issue arises from a missing capability check in the wc4bp_delete_page() function, allowing authenticated attackers with Subscriber-level access and above to unauthorizedly modify the plugin's page settings.
Exploitation of this vulnerability allows for unauthorized modification of the plugin's page settings by authenticated users with Subscriber-level access or higher.
Users are advised to update the plugin to version 3.4.25 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.