BuddyPress Groupblog
BuddyPress Groupblog has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Improper Privilege Management, behind 1 of the records (100%).
The one issue recorded for BuddyPress Groupblog has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. BuddyPress Groupblog is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.3.
CVE-2026-5144BuddyPress Groupblog <= 1.9.3 - Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR
Read the full analysisVulnerability Records
BuddyPress Groupblog
Author
Boone Gorges
Requires BuddyPress 1.7+ and PHP 5.3+. The BuddyPress Groupblog plugin extends the group functionality by enabling each group to have a single blog associated with it. Group members are automatically added to the blog and will have blog roles as set by the groupblog admin settings. Features: P2 integration and frontend posting. Admin can set Template specific groupblogs. Allow group admins choose the desired template page themselves. Full blog theme integration. The included bp-groupblog theme mimics the group pages. Automated blog registration at group creation stage. Bypass default blog validation to allow dashes, underscores, numeral only and minimum character count. Blog privacy settings are initially inherited from group privacy settings. Group members are automatically added to the blog. Blog roles match group roles as set by the group admin. Solid error checking that the blog follows validation. Group admin tab to access the group-blog settings. Blog themes will have the ability to pull in group info and create a theme that could resemble the group exactly. Leaving the group will downgrade the member role to ‘subscriber’. Allow the group admin to select one of his/her existing blogs. A new ajax backend.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C