PT-2025-45542 · WordPress · Plugin Groups

Angus Girvan

·

Published

2025-11-08

·

Updated

2025-11-11

·

CVE-2025-11748

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Groups plugin for WordPress versions prior to 6.7.1
Description The Groups plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. This flaw stems from inadequate validation of a user-controlled key, specifically the group id parameter within the group join function. Authenticated attackers possessing Subscriber-level access or higher can exploit this to join groups beyond those designated in the shortcode. The vulnerable parameter is group id.
Recommendations Update the Groups plugin to version 6.7.1 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11748

Affected Products

Plugin Groups