CVE-2026-5144Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user input without proper authorization checks. The `groupblog-blogid` parameter allows any group admin (including Subscribers who create their own group) to associate their group with any blog on the Multisite network, including the main site (blog ID 1). The `default-member` parameter accepts any WordPress role, including `administrator`, without validation against a whitelist. When combined with `groupblog-silent-add`, any user who joins the attacker's group is automatically added to the targeted blog with the injected role. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate any user (including themselves via a second account) to Administrator on the main site of the Multisite network.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-11); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-11: 4Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-18: 1Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-11: 404-1104-18
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-114
Disclosure3Patch1
2026-04-181
PoC1
Full discourse5 posts
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-5144 lets BuddyPress Groupblog users escalate privileges from Subscriber to Admin. This vulnerability is critical and actively exploited. Patch now to prevent unauthorized access and potential data breaches. #NerdieNews #CyberSecurity #InfoSec #WordPress #DevSecOps

    Post summary

    CVE-2026-5144 allows BravoPress Groupblog users to elevate privileges from Subscriber to Admin. Immediate patching is required to stop ongoing exploitation and prevent unauthorized access and data breaches.

    0001087
    55 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5144-bp-groupblog-version-1-9-3-high-vulnerability-proof-of-concept CVE-2026-5144 #WordPress plugin #vulnerability bp-groupblog #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑5144 targeting the bp‑groupblog WordPress plugin; it focuses on the demonstration of the vulnerability rather than active exploitation, patches, or technical depth.

    0000031
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5144 The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings … https://www.cve.org/CVERecord?id=CVE-2026-5144

    Post summary

    CVE-2026-5144 reveals a privilege‑escalation vulnerability in BuddyPress Groupblog plugin versions up to 1.9.3, triggered by group blog settings; the CVE record link provides further details.

    00000168
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5144 Privilege Escalation in BuddyPress Groupblog Plugin for WordPress Up to 1.9.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5144

    Post summary

    The text announces a privilege escalation vulnerability in BuddyPress Groupblog Plugin up to version 1.9.3, providing basic technical details but no proofs, exploits, or patches.

    0000042
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5144: HIGH] BuddyPress Groupblog plugin for WordPress up to version 1.9.3 is susceptible to Privilege Escalation, enabling authenticated attackers to elevate users to Administrators on a Multisite ne...#cve,CVE-2026-5144,#cybersecurity https://cvefind.com/CVE-2026-5144

    Post summary

    The post announces a new privilege escalation vulnerability (CVE-2026-5144) in BuddyPress Groupblog plugin up to version 1.9.3 that allows authenticated users on multisite WordPress installs to become administrators.

    0000054
    619 followersView on X

Explore more