Vulnerabilities / BuddyPress Member Reviews / WPSEC-2026-0751
BuddyPress Member Reviews <= 3.8.0 - Authenticated (Subscriber+) Missing Authorization to Moderation Bypass via Review Update
Medium 4.3
CWE-862Fixed in 3.8.1
- ID
- WPSEC-2026-0751
- Plugin
- Wbcom Designs – BuddyPress Member Reviews (bp-user-profile-reviews)
- Affected
- all versions before 3.8.1
- Remediation
- Update to 3.8.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- BuddyPress Member Reviews on WPSec AttackSurface
- Fix released
- Published
Description
The BuddyPress Member Reviews plugin for WordPress is vulnerable to a moderation bypass in all versions up to, and including, 3.8.0 due to the review update handler forcing the review's status to 'publish' on every edit and the Update Review setting only being enforced by hiding the Edit button. This makes it possible for authenticated attackers who wrote a review to edit a pending or report-hidden review and have it published immediately without moderator approval.
References
- https://wpsec.com/vuln/WPSEC-2026-0751/
- https://plugins.svn.wordpress.org/bp-user-profile-reviews/tags/3.8.1/
- https://wordpress.org/plugins/bp-user-profile-reviews/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS