CVE-2025-1780

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 1, 2025
CWE ID 862

Summary

CVE-2025-1780: A vulnerability affects the BuddyPress WooCommerce My Account Integration plugin for WordPress. The issue lies in the wc4bp_delete_page() function, which lacks necessary capability checks. This flaw enables authenticated attackers with Subscriber-level access and above to update the plugin's page settings unauthorizedly, potentially putting the website at risk. Versions up to and including 3.4.25 are vulnerable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share