Junglewise Threat Intelligence

CVE-2026-5144: BuddyPress Groupblog privilege escalation in group blog settings

CVE-2026-5144 · Severity: high · CVSS 8.8 · Published 2026-04-11

Executive brief

The BuddyPress Groupblog plugin for WordPress, which connects community groups to specific blogs, contains a security flaw that allows low-level users to gain administrative control. By creating a group and manipulating hidden settings, an attacker can link their group to the main website and grant themselves or others full Administrator privileges. This could lead to a complete takeover of the WordPress site and its data.

Technical details

The BuddyPress Groupblog plugin fails to perform proper authorization and validation checks on the 'groupblog-blogid', 'default-member', and 'groupblog-silent-add' parameters within its group blog settings handler. An authenticated attacker with Subscriber-level permissions can create a group and maliciously associate it with any blog ID in a Multisite network (including the main site, ID 1). By setting the 'default-member' parameter to 'administrator' and enabling 'groupblog-silent-add', any user joining the attacker's group is automatically granted the Administrator role on the targeted blog. This allows for full site takeover via privilege escalation.

Affected products

  • boonebgorges BuddyPress Groupblog Up to and including 1.9.3

Timeline

  • 2026-04-10: advisory: Wordfence published vulnerability details
  • 2026-04-11: disclosed: NVD publication date

References