CVE-2024-13358
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 1, 2025
CWE ID 862
Summary
CVE-2024-13358 is a vulnerability affecting the BuddyPress WooCommerce My Account Integration plugin for WordPress. This issue allows authenticated attackers, including those with Subscriber-level access, to gain unauthorized access and modify the plugins page settings. The root cause is a missing capability check in the wc4bp_delete_page() function, affecting all versions up to and including 3.4.24. This vulnerability poses a significant risk to websites using this plugin and should be addressed promptly by updating to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.