PT-2026-99411 · WordPress · Groups – Memberships/Access Control
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Groups – Memberships and Access Control versions prior to 4.6.1
Description
An issue exists where the
groups join() function determines group-join eligibility based on the author capabilities of the ambient post via the global $post->post author instead of the authenticated user's own capabilities. Because the system returns a valid groups-join-data hash and WordPress nonce in the same response, authorization barriers for self-enrollment are removed. Authenticated attackers with Subscriber-level access or higher can enroll themselves in any group, including those with the groups admin groups capability. By creating and joining a group containing all registered WordPress capabilities, an attacker can escalate their privileges to Administrator. This is achieved by providing an Administrator-authored post ID through the post ID parameter of the wp ajax parse media shortcode handler to establish a privileged context for the authorization check.Recommendations
Update Groups – Memberships and Access Control to a version newer than 4.6.0.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Groups – Memberships/Access Control