VYPR

Groups

by WordPress

Source repositories

CVEs (3)

  • CVE-2026-77203HigSep 26, 2026
    risk 0.50cvss 8.8epss 0.00

    The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the…

  • CVE-2026-0549MedFeb 19, 2026
    risk 0.42cvss 6.4epss 0.00

    The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

  • CVE-2025-11748MedNov 8, 2025
    risk 0.28cvss 4.3epss 0.00

    The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.0 via the 'group_id' parameter of the group_join function due to missing validation on a user controlled key. This makes it possible for authenticated…