BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation
2021-03-16 00:00
AnonymousStrategic Overview
Vulnerability Overview
The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.
Technical Analysis
REMEDIATION: Update to version 7.2.1, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C