Wbcom Designs – BuddyPress Group Reviews <= 2.8.3 - Unauthorized AJAX Actions due to Nonce Bypass

2022-06-16 00:00
Marco Wotschka

Strategic Overview

Status
Patched in 2.8.4
Affected Version<= 2.8.3
CVSS6.5Medium
CVECVE-2022-2108
View all Wbcom Designs – BuddyPress Group Reviews vulnerabilities

Vulnerability Overview

The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.

Technical Analysis

REMEDIATION: Update to version 2.8.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C