VYPR

Buddypress Woocommerce My Account Integration

by WordPress

CVEs (2)

  • CVE-2024-2025HigMar 23, 2024
    risk 0.50cvss 8.8epss 0.01

    The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.20 via deserialization of untrusted input in the get_simple_request function. This makes it…

  • CVE-2025-1780Mar 1, 2025
    risk 0.00cvss epss 0.00

    The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible…