CVE-2014-1889: Buddypress

Medium severity, CVSS 6.5. EPSS: 10.6% chance of exploitation in the next 30 days.

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.

Affected products

  • Buddypress Buddypress: before 1.9.2 (fixed in 1.9.2)

Published 2018-04-10. Last modified 2026-06-17.