Wbcom Designs – BuddyPress Group Reviews <= 2.8.3 - Unauthorized AJAX Actions due to Nonce Bypass
2022-06-16 00:00
Marco WotschkaStrategic Overview
StatusPatched in 2.8.4
Affected PluginWbcom Designs – BuddyPress Group Reviews
Affected Version
<= 2.8.3CVSS6.5Medium
CVE
CVE-2022-2108Vulnerability Overview
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.
Technical Analysis
REMEDIATION: Update to version 2.8.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C