Description
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
Published: 2025-03-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Settings Modification
Action: Update
AI Analysis

Impact

The BuddyPress WooCommerce My Account Integration plugin for WordPress is missing a capability check in its wc4bp_delete_page() function. This flaw allows any authenticated user who holds a Subscriber role or higher to invoke the function and alter the plugin’s page settings. The vulnerability does not enable arbitrary code execution or data exfiltration, but it can disrupt the intended configuration of member pages and potentially affect the visibility or ordering of WooCommerce content for users. The CVSS score of 4.3 reflects a moderate severity, indicating that the impact is limited but still significant for e-commerce sites relying on the correct presentation of member pages.

Affected Systems

Affected systems are installations of the BuddyPress WooCommerce My Account Integration plugin, developed by Themekraft, for WordPress. Vulnerable versions run up to and including 3.4.25. The CPE reference identifies the product as a WordPress plugin environment.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, pointing to a relatively low likelihood of public exploitation. Nonetheless, the flaw requires only that the attacker is authenticated with at least Subscriber-level permissions—an access level that many site users possess. Once authenticated, the attacker can modify plugin settings through the exposed endpoint, potentially altering the user experience or compromising site configuration. The moderate CVSS score signals that proactive patching is warranted, even though the risk of exploitation in the wild is low.

Generated by OpenCVE AI on April 21, 2026 at 22:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official update from Themekraft that addresses the missing capability check.
  • If no update is available, restrict Subscriber role capabilities that permit accessing plugin settings or add a custom capability filter to block wc4bp_delete_page() calls.
  • Monitor Themekraft security releases for a fix and plan to apply it as soon as released.

Generated by OpenCVE AI on April 21, 2026 at 22:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5912 The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
History

Mon, 26 May 2025 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Themekraft
Themekraft buddypress Woocommerce My Account Integration
CPEs cpe:2.3:a:themekraft:buddypress_woocommerce_my_account_integration:*:*:*:*:*:wordpress:*:*
Vendors & Products Themekraft
Themekraft buddypress Woocommerce My Account Integration

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 01 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Description The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
Title BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.25 - Cross-Site Request Forgery to Limited Settings Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Themekraft Buddypress Woocommerce My Account Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:27:43.855Z

Reserved: 2025-02-28T15:20:33.379Z

Link: CVE-2025-1780

cve-icon Vulnrichment

Updated: 2025-03-03T20:53:32.936Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-01T04:15:09.713

Modified: 2025-05-26T01:36:29.360

Link: CVE-2025-1780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T22:15:45Z

Weaknesses