Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-1889. PoCs published by Pietro Oliva.
AI-analyzed exploit summary This exploit describes a privilege escalation vulnerability in BuddyPress <= 1.9.1 due to insufficient permission checks during group creation. An attacker can manipulate a cookie to gain control over existing groups.
Description
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Exploits (1)
This exploit describes a privilege escalation vulnerability in BuddyPress <= 1.9.1 due to insufficient permission checks during group creation. An attacker can manipulate a cookie to gain control over existing groups.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N