CVE-2024-13358: BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.24 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bpdeletepage() function in all versions up to, and including, 3.4.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13358?
CVE-2024-13358 has a medium severity rating due to the potential for unauthorized access.
How do I fix CVE-2024-13358?
To fix CVE-2024-13358, update the BuddyPress WooCommerce My Account Integration plugin to version 3.4.25 or later.
What versions are affected by CVE-2024-13358?
CVE-2024-13358 affects all versions of BuddyPress WooCommerce My Account Integration up to and including 3.4.24.
What is the nature of the vulnerability in CVE-2024-13358?
CVE-2024-13358 is caused by a missing capability check in the wc4bp_delete_page() function, allowing unauthorized access.
Who is impacted by CVE-2024-13358?
Users of the BuddyPress WooCommerce My Account Integration plugin on WordPress who have versions up to 3.4.24 are impacted by CVE-2024-13358.