CVE-2022-2108: Wbcom Designs – BuddyPress Group Reviews <= 2.8.3 - Unauthorized AJAX Actions due to Nonce Bypass
The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and review modification due to missing capability checks and improper nonce checks in several functions related to said actions in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to modify reviews and plugin settings on the affected site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-2108?
CVE-2022-2108 is a vulnerability in the Wbcom Designs – BuddyPress Group Reviews for WordPress plugin that allows for unauthorized settings changes and review modification.
What software is affected by CVE-2022-2108?
The Wbcom Designs – BuddyPress Group Reviews for WordPress plugin versions up to and including 2.8.3 are affected.
What is the severity of CVE-2022-2108?
CVE-2022-2108 has a severity rating of medium with a score of 6.5 (CVSS:3.0).
How can CVE-2022-2108 be exploited?
CVE-2022-2108 can be exploited by attackers to make unauthorized settings changes and modify reviews in the vulnerable plugin.
Are there any references for CVE-2022-2108?
Yes, you can find references for CVE-2022-2108 at the following links: [link1](https://www.wordfence.com/threat-intel/vulnerabilities/id/397dabc3-5dcf-4d1f-9e24-28af889cb76f?source=cve), [link2](https://plugins.trac.wordpress.org/browser/review-buddypress-groups/trunk/includes/bgr-ajax.php#L359), [link3](https://plugins.trac.wordpress.org/changeset/2742109).