Insecure Direct Object Reference Vulnerability in Groups Plugin for WordPress
CVE-2025-11748
4.3MEDIUM
What is CVE-2025-11748?
The Groups plugin for WordPress is susceptible to an Insecure Direct Object Reference, stemming from inadequate validation of the 'group_id' parameter in the group_join function. This vulnerability allows authenticated attackers, even those with Subscriber-level access, to manipulate requests and join groups outside their intended permissions, potentially compromising user privacy and group integrity.
Affected Version(s)
Groups * <= 6.7.0