PT-2025-1752 · WordPress · Youzify – Buddypress Community

Brian Mungai

·

Published

2025-01-25

·

Updated

2025-01-25

·

CVE-2024-12113

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress versions up to, and including, 1.3.2
Description The issue is related to unauthorized loss of data due to a missing capability check on the delete user review() and delete review() functions. This allows authenticated attackers with Subscriber-level access and above to delete other users' reviews.
Recommendations For versions up to, and including, 1.3.2, consider disabling the delete user review() and delete review() functions until a patch is available to prevent unauthorized deletion of user reviews. Restrict access to these functions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-12113

Affected Products

Youzify – Buddypress Community