CVE-2026-77203P2HIGHCVSS 8.8≤ 4.6.02026-09-26
CVE-2026-77203 [HIGH] CWE-269 CVE-2026-77203: The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalati
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's o
nvd