The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Buddypress | Buddypress | * | 1.9.2 (excluding) |