20140213 Wordpress plugin Buddypress <= 1.9.1 privilege escalation vulnerabilitymailing list
http://www.securityfocus.com/archive/1/531050/100/0/threaded CVE-2014-1889
MEDIUM
WordPress Plugin BuddyPress 1.9.1 - Privilege Escalation
Record summary
CVE-2014-1889 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin BuddyPress 1.9.1 - Privilege EscalationExploitDB exploitby Pietro OlivaNot analyzed1 file
References
565554vdb entry
http://www.securityfocus.com/bid/65554 buddypress.orgConfirmation
https://buddypress.org/2014/02/buddypress-1-9-2 buddypress-cve20141889-sec-bypass(91261)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/91261 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-1889