CVE-2025-1780 Details
Description
The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wc4bp_delete_page() function in all versions up to, and including, 3.4.25. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins page setting.
A vulnerability exists in the BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress, in versions through 3.4.25. The issue arises from a missing capability check in the wc4bp_delete_page() function, allowing authenticated attackers with Subscriber-level access or higher to unauthorized access. This vulnerability enables them to update the plugin's page settings.
Users are advised to update the BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin to version 3.4.26 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| themekraft buddypress woocommerce my account integration | < 3.4.26 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2025 | Initial Analysis | [email protected] |
| Mar 1, 2025 | New CVE Received | [email protected] |