BuddyPress Member Reviews <= 3.8.0 - Authenticated (Subscriber+) Missing Authorization to Review Submission Role Restriction Bypass

Medium 4.3 CWE-862Fixed in 3.8.1
ID
WPSEC-2026-0749
Plugin
Wbcom Designs – BuddyPress Member Reviews (bp-user-profile-reviews)
Affected
all versions before 3.8.1
Remediation
Update to 3.8.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
BuddyPress Member Reviews on WPSec AttackSurface
Fix released
Published

Description

The BuddyPress Member Reviews plugin for WordPress is vulnerable to unauthorized review submission in all versions up to, and including, 3.8.0 due to the submit-review handler not enforcing the Reviewer Roles and Reviewee Roles settings server-side, relying only on hiding the Add Review button. This makes it possible for authenticated attackers with Subscriber-level access and above to submit reviews from a disallowed role or to members whose role is excluded from receiving reviews, and to post anonymous reviews even when Anonymous Reviews is disabled.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0