CVE-2024-13358
BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages
Minimum safe version
3.4.26
Update to 3.4.26 or later to address 13 fixable vulnerabilities
WordPress WooBuddy Plugin <= 3.4.25 is vulnerable to Cross Site Request Forgery (CSRF)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-35726
CVE-2024-32603
CVE-2024-2025
WordPress WooBuddy Plugin <= 3.4.15 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress WooBuddy -> WooCommerce BuddyPress Integration plugin <= 3.4.1 - Sensitive Information Disclosure vulnerability
WordPress WooBuddy -> WooCommerce BuddyPress Integration plugin <= 3.4.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability