PT-2026-99411 · WordPress · Groups – Memberships/Access Control

·

CVE-2026-77203

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Groups – Memberships and Access Control versions prior to 4.6.1
Description An issue exists where the groups join() function determines group-join eligibility based on the author capabilities of the ambient post via the global $post->post author instead of the authenticated user's own capabilities. Because the system returns a valid groups-join-data hash and WordPress nonce in the same response, authorization barriers for self-enrollment are removed. Authenticated attackers with Subscriber-level access or higher can enroll themselves in any group, including those with the groups admin groups capability. By creating and joining a group containing all registered WordPress capabilities, an attacker can escalate their privileges to Administrator. This is achieved by providing an Administrator-authored post ID through the post ID parameter of the wp ajax parse media shortcode handler to establish a privileged context for the authorization check.
Recommendations Update Groups – Memberships and Access Control to a version newer than 4.6.0.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77203

Affected Products

Groups – Memberships/Access Control