CVE-2026-5144 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 11, 2026
BuddyPress Groupblog - Privilege Escalation
Overview
BuddyPress Groupblog plugin for WordPress <= 1.9.3 contains a privilege escalation caused by improper authorization checks on group blog settings parameters, letting authenticated group admins escalate user roles including to Administrator, exploit requires authenticated Subscriber or higher.
Severity & Score
Impact
Authenticated attackers can escalate any user to Administrator on the main Multisite network site, leading to full site compromise.
Mitigation
Update to a version later than 1.9.3 or the latest available version.
References
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php#L190
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php#L220
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php#L450
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8129046a-5aa5-4644-babc-0eca9aa524d2?source=cve
- https://github.com/boonebgorges/bp-groupblog/commit/b824593add9e2c53ef4f0d2e0824d4de0785411f
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php#L190
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php#L220
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php#L450
Social Media Activity(4 posts)
š© HIGH severity: CVE-2026-5144 impacts BuddyPress Groupblog ā¤1.9.3. Authenticated users (even Subscribers) can escalate to Admin on WordPress Multisite. No patch yet ā disable or restrict plugin for now. https://radar.offseq.com/threat/cve-2026-5144-cwe-269-improper-privilege-managemen-f1535bf6 #OffSeq #WordPress #CVE20265144 #infosec
View original postš CVE-2026-5144 - High (8.8) The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-sile... š https://www.thehackerwire.com/vulnerability/CVE-2026-5144/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš© HIGH severity: CVE-2026-5144 impacts BuddyPress Groupblog ā¤1.9.3. Authenticated users (even Subscribers) can escalate to Admin on WordPress Multisite. No patch yet ā disable or restrict plugin for now. https://radar.offseq.com/threat/cve-2026-5144-cwe-269-improper-privilege-managemen-f1535bf6 #OffSeq #WordPress #CVE20265144 #infosec
View original postš CVE-2026-5144 - High (8.8) The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-sile... š https://www.thehackerwire.com/vulnerability/CVE-2026-5144/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-5144
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- new
- EPSS
- 4.9%
- Social Posts
- 4
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H