Description
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify reviews and plugin settings on the website. WordPress Plugin Wbcom Designs-BuddyPress Group Reviews version 2.8.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.8.4 or latest
References
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2108
https://plugins.svn.wordpress.org/review-buddypress-groups/trunk/readme.txt
Related Vulnerabilities
TYPO3 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-3633)
WordPress Plugin Wechat Broadcast Local/Remote File Inclusion (1.2.0)
Drupal Core 8.5.x Remote Code Execution (8.5.0 - 8.5.2)
WordPress Plugin AdServe 'id' Parameter SQL Injection (0.2)
WordPress Plugin Category Order and Taxonomy Terms Order PHP Object Injection (1.5.2.2)