PT-2026-32089 · WordPress · Buddypress Groupblog+1
Nabil Irawan
·
Published
2026-04-11
·
Updated
2026-04-11
·
CVE-2026-5144
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BuddyPress Groupblog plugin for WordPress versions up to and including 1.9.3
Description
The BuddyPress Groupblog plugin for WordPress is susceptible to Privilege Escalation. The group blog settings handler accepts the
groupblog-blogid, default-member, and groupblog-silent-add parameters from user input without proper authorization checks. The groupblog-blogid parameter allows group admins to associate their group with any blog on the Multisite network, including the main site. The default-member parameter accepts any WordPress role, including administrator, without validation. When combined with groupblog-silent-add, any user who joins the attacker's group is automatically added to the targeted blog with the injected role. This allows attackers with Subscriber-level access and above to escalate users to Administrator on the main site of the Multisite network.Recommendations
Update BuddyPress Groupblog plugin to a version later than 1.9.3.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buddypress Groupblog
Wordpress