CVE-2014-1889: Medium severity buddypress vulnerability
Published Apr 10, 2018
·Updated
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Affected Software
1 affected component
BuddyPress Buddypress Wordpress<1.9.2
Event History
Apr 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1889?
CVE-2014-1889 has a medium severity rating due to the risk of unauthorized access to group control.
2
How do I fix CVE-2014-1889?
To fix CVE-2014-1889, update the BuddyPress plugin to version 1.9.2 or later.
3
Who is affected by CVE-2014-1889?
Remote authenticated users of BuddyPress versions prior to 1.9.2 are at risk of exploiting this vulnerability.
4
What type of vulnerability is CVE-2014-1889?
CVE-2014-1889 is a privilege escalation vulnerability related to missing permission checks during group creation.
5
Is there a workaround for CVE-2014-1889 if I can't update?
There are no recommended workarounds for CVE-2014-1889, so updating to the latest version is essential.