CVE-2014-1889
UnknownEPSS 10.82%
Last modified
CVE-2014-1889 is a vulnerability of currently unknown severity. The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.. EPSS estimates a 10.82% chance of exploitation in the next 30 days.
Description
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Buddypress | Buddypress | < 1.9.2 |
References
- http://www.securityfocus.com/archive/1/531050/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/65554Third Party Advisory, VDB Entry
- https://buddypress.org/2014/02/buddypress-1-9-2/Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91261Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/531050/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/65554Third Party Advisory, VDB Entry
- https://buddypress.org/2014/02/buddypress-1-9-2/Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91261Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1889?
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
How severe is CVE-2014-1889?
Severity scoring for CVE-2014-1889 is pending analysis. The EPSS model estimates a 10.82% probability of exploitation in the next 30 days.
How do I fix CVE-2014-1889?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-1883Adobe PhoneGap before 2.6.0 on Android uses the shouldOverri…
- CVE-2014-1884Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 an…
- CVE-2014-1885The ForzeArmate application for Android, when Adobe PhoneGap…
- CVE-2014-1886The Edinburgh by Bus application for Android, when Adobe Pho…
- CVE-2014-1887The DrinkedIn BarFinder application for Android, when Adobe …
- CVE-2014-1888Cross-site scripting (XSS) vulnerability in the BuddyPress p…
- CVE-2014-1891Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLA…
- CVE-2014-1892Xen 3.3 through 4.1, when XSM is enabled, allows local users…
- CVE-2014-1893Multiple integer overflows in the (1) FLASK_GETBOOL and (2) …
- CVE-2014-1894Multiple integer overflows in unspecified suboperations in t…
- CVE-2014-1895Off-by-one error in the flask_security_avc_cachestats functi…
- CVE-2014-1896The (1) do_send and (2) do_recv functions in io.c in libvcha…
Are you affected by CVE-2014-1889?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
