Description
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify reviews and plugin settings on the website. WordPress Plugin Wbcom Designs-BuddyPress Group Reviews version 2.8.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8.4 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2108
https://plugins.svn.wordpress.org/review-buddypress-groups/trunk/readme.txt
Related Vulnerabilities
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2335)
Drupal Core 8.x.x Directory Traversal (8.0.0 - 8.8.12)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3541)
WordPress Plugin Spreadsheet (wpSS) Cross-Site Scripting (0.62)
WordPress Plugin GD bbPress Attachments Cross-Site Scripting (2.5)