CVE-2025-1780: BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.25 - Cross-Site Request Forgery to Limited Settings Update
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bpdeletepage() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1780?
CVE-2025-1780 is considered a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2025-1780?
To fix CVE-2025-1780, you should update the BuddyPress WooCommerce My Account Integration plugin to version 3.4.26 or later.
What versions are affected by CVE-2025-1780?
CVE-2025-1780 affects all versions of the BuddyPress WooCommerce My Account Integration plugin up to and including 3.4.25.
What functionality is compromised due to CVE-2025-1780?
The wc4bp_delete_page() function in the BuddyPress WooCommerce My Account Integration plugin lacks a capability check, leading to unauthorized access.
Is CVE-2025-1780 publicly known?
Yes, CVE-2025-1780 has been publicly disclosed and can be referenced in various cybersecurity databases.