Executive brief
The BuddyPress Groupblog plugin for WordPress, which connects community groups to specific blogs, contains a security flaw that allows low-level users to gain administrative control. By creating a group and manipulating hidden settings, an attacker can link their group to the main website and grant themselves or others full Administrator privileges. This could lead to a complete takeover of the WordPress site and its data.
Technical details
The BuddyPress Groupblog plugin fails to perform proper authorization and validation checks on the 'groupblog-blogid', 'default-member', and 'groupblog-silent-add' parameters within its group blog settings handler. An authenticated attacker with Subscriber-level permissions can create a group and maliciously associate it with any blog ID in a Multisite network (including the main site, ID 1). By setting the 'default-member' parameter to 'administrator' and enabling 'groupblog-silent-add', any user joining the attacker's group is automatically granted the Administrator role on the targeted blog. This allows for full site takeover via privilege escalation.
Affected products
- boonebgorges BuddyPress Groupblog Up to and including 1.9.3
Timeline
- 2026-04-10: advisory: Wordfence published vulnerability details
- 2026-04-11: disclosed: NVD publication date
References
- https://github.com/boonebgorges/bp-groupblog/commit/b824593add9e2c53ef4f0d2e0824d4de0785411f
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php
- https://plugins.trac.wordpress.org/browser/bp-groupblog/tags/1.9.3/bp-groupblog.php
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php
- https://plugins.trac.wordpress.org/browser/bp-groupblog/trunk/bp-groupblog.php