plugin

Bp Groupblog Vulnerabilities

1 known security issue reported for the Bp Groupblog WordPress plugin. Most recent disclosed Apr 10, 2026.

1 high

Running Bp Groupblog on your site? Check whether your installed version is affected.

Scan your site free

BuddyPress Groupblog <= 1.9.3 - Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR

high

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user input without proper authorization checks. T...

CVSS:
8.8
Affected:
up to 1.9.3
Fixed in:
1.9.4
Disclosed:
Apr 10, 2026

CVE-2026-5144 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database