BuddyPress - 7.0.0 - 7.2.0 - Insufficient Privilege De-escalation

2021-03-16 00:00
Anonymous

Strategic Overview

Status
Patched in 7.2.1
Affected PluginBuddyPress
Affected Version7.0.0 – < 7.2.1
CVSS4.6Medium
CVEN/A
View all BuddyPress vulnerabilities

Vulnerability Overview

The BuddyPress plugin for WordPress was vulnerable to authorization bypass due to a misconfiguration in how the plugin handled downgrading administrative level users to subscriber level in versions 7.0.0 - 7.2.0. This allowed subscriber level users to modify BuddyPress Member Types.

Technical Analysis

REMEDIATION: Update to version 7.2.1, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C