VYPR

Groups – Memberships and Access Control

by WordPress

CVEs (1)

  • CVE-2026-77203HigSep 26, 2026
    risk 0.50cvss 8.8epss —

    The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the…