CVE-2014-1889

MEDIUM

Buddypress <1.9.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-1889. PoCs published by Pietro Oliva.

AI-analyzed exploit summary This exploit describes a privilege escalation vulnerability in BuddyPress <= 1.9.1 due to insufficient permission checks during group creation. An attacker can manipulate a cookie to gain control over existing groups.

Description

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.

Exploits (1)

exploitdb WRITEUP
by Pietro Oliva · textwebappsphp
https://www.exploit-db.com/exploits/31571

This exploit describes a privilege escalation vulnerability in BuddyPress <= 1.9.1 due to insufficient permission checks during group creation. An attacker can manipulate a cookie to gain control over existing groups.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: BuddyPress <= 1.9.1
Auth required
Prerequisites: Valid user session · Access to group creation URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/531050/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91261
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65554
Vendor Advisory x_refsource_confirm
https://buddypress.org/2014/02/buddypress-1-9-2/

Scores

CVSS v3 6.5
EPSS 0.1082
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-264
Status published
Products (1)
buddypress/buddypress < 1.9.2
Published Apr 10, 2018
Tracked Since Feb 18, 2026