CVE-2025-1780
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 1, 2025
CWE ID 862
Summary
CVE-2025-1780: A vulnerability affects the BuddyPress WooCommerce My Account Integration plugin for WordPress. The issue lies in the wc4bp_delete_page() function, which lacks necessary capability checks. This flaw enables authenticated attackers with Subscriber-level access and above to update the plugin's page settings unauthorizedly, potentially putting the website at risk. Versions up to and including 3.4.25 are vulnerable.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.