Description
WordPress Plugin WooCommerce BuddyPress Integration is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently perform a variety of the plugin's actions or even take over a website. WordPress Plugin WooCommerce BuddyPress Integration version 3.2.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6 or latest
References
Related Vulnerabilities
Apache version older than 1.3.39
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-1581)
WordPress Plugin Widget Logic Cross-Site Request Forgery (5.9.0)
Dolphin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4333)
WordPress Plugin Royal PrettyPhoto Cross-Site Scripting (1.2)