Description
BuddyPress is an open-source social networking software package owned by Automattic since 2008. It is a plugin that can be installed on WordPress to transform it into a social network platform.
A vulnerability exists in BuddyPress versions before 7.2.1 that could allow a privilege escalation from a regular user to Administrator, using the BuddyPress REST API buddypress/v1/members/me endpoint.
Remediation
Upgrade to BuddyPress version 7.2.1.
References
Related Vulnerabilities
Zenphoto Improper Privilege Management Vulnerability (CVE-2018-0610)
WordPress Plugin Malware Scanner Privilege Escalation (4.7.2)
WordPress Plugin Donations Privilege Escalation (1.3)
WordPress Plugin Login as User or Customer Privilege Escalation (3.2)
WordPress Plugin Store Locator Plus for WordPress Privilege Escalation (5.5.14)