← WordPress Vulnerabilities
WordPress security by component

"BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages"

"BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 23, 2024; the highest published CVSS base score is 8.8.

Plugin slug: buddypress-woocommerce-my-account-integration-create-woocommerce-member-pages

CVE-2024-2025: "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages": Code execution

"BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" is affected by code execution. Exploitation requires an authenticated subscriber account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedMar 23, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for buddypress-woocommerce-my-account-integration-create-woocommerce-member-pages
Safe version
Mar 23, 2024 CVE-2024-2025
"BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages": Code execution
"BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" is affected by code execution. Exploitation requires an authenticated subscriber account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending