Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77203— Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode

Quick assessment

Affected
itthinx Groups – Memberships and Access Control
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 “Groups – Memberships and Access Control” 存在权限提升漏洞,影响所有 4.6.0 及更早版本。该漏洞源于 函数在判断用户是否有资格加入某个组时,错误地依赖于当前页面的全局 (即该文章的作者)的权限,而非当前已认证用户的自身权限。同时,该函数在同一响应中向调用者颁发并返回一个有效的 “groups-join-data” 哈希值和 WordPress Nonce,从而彻底绕过了所有授权检查机制,使攻击者能够自行加入任意组别。 利用此漏洞,具备 Subs

CVSS 8.8 · High EPSS 0.33% · P23
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77203

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode
Source: CVE Program / CVE List V5
Vulnerability Description
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting and returning a valid groups-join-data hash and WordPress nonce for the caller in the same response — eliminating all authorization barriers to self-enrollment. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enroll themselves into any group including privileged groups carrying the groups_admin_groups capability, and to subsequently create and join a group containing every registered WordPress capability, effectively escalating their privileges to Administrator. Exploitation requires the attacker to supply an Administrator-authored post ID via the post_ID parameter of the authenticated wp_ajax_parse_media_shortcode handler in order to establish the privileged ambient post context used by the flawed authorization check.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
itthinx Groups – Memberships and Access Control 0 ~ 4.6.0 -

II. Public POCs for CVE-2026-77203

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77203

请登录查看更多情报信息。

News Coverage for CVE-2026-77203 (1)

Other References for CVE-2026-77203 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77203

No comments yet


Leave a comment