BuddyPress <= 1.9.1 - Authorization Bypass

2014-02-05 00:00
Pietro Oliva

Strategic Overview

Status
Patched in 1.9.2
Affected PluginBuddyPress
Affected Version< 1.9.2
CVSS6.5Medium
CVECVE-2014-1889
View all BuddyPress vulnerabilities

Vulnerability Overview

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. An attacker could exploit this vulnerability to modify the name, description, avatar and settings of groups.

Technical Analysis

REMEDIATION: Update to version 1.9.2, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C