Description
Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery.This issue affects BuddyPress Groups Extras: from n/a through <= 3.6.10.
Published: 2025-01-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The BuddyPress Groups Extras plugin contains a CSRF flaw that enables an attacker to trigger authenticated requests on behalf of a logged‑in user. The flaw can be exploited by sending a crafted request from a malicious site or by tricking an authenticated user into visiting a specific link. As a result, an attacker could alter the plugin’s state, potentially adding or removing group members, changing group settings, or performing other privileged actions. This weakness is identified as CWE‑352.

Affected Systems

The vulnerability affects the BuddyPress Groups Extras plugin developed by Slava Abakumov. Versions up to and including 3.6.10 are vulnerable, and any WordPress site that has this plugin installed with a version at or below 3.6.10 is at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity vulnerability, while the EPSS score is less than 1%, indicating a very low probability of exploitation at present. The vulnerability has not been listed in CISA KEV, suggesting no known widespread exploitation. Attackers would need to entice a logged‑in user to trigger a request to the vulnerable plugin, such as by clicking a malicious link or loading a malicious script that issues a POST request. If exploited, the attacker could perform arbitrary changes to group membership or settings on the victim’s site, but the low EPSS and lack of active exploitation in the wild mean the immediate risk to the average site is moderate, warranting timely remediation.

Generated by OpenCVE AI on May 2, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BuddyPress Groups Extras to a version newer than 3.6.10.
  • If an upgrade is not feasible, ensure that any state‑modifying actions in the plugin are protected by WordPress nonces or other CSRF tokens; if not, consider disabling those actions or the plugin entirely until patched.
  • Verify that the WordPress installation and all other plugins use up‑to‑date CSRF protection mechanisms and enable additional layers such as two‑factor authentication for privileged accounts.

Generated by OpenCVE AI on May 2, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3750 Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10. Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery.This issue affects BuddyPress Groups Extras: from n/a through <= 3.6.10.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 14:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10.
Title WordPress BuddyPress Groups Extras plugin <= 3.6.10 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:20:55.445Z

Reserved: 2025-01-23T14:50:05.372Z

Link: CVE-2025-24538

cve-icon Vulnrichment

Updated: 2025-02-12T19:53:28.482Z

cve-icon NVD

Status : Deferred

Published: 2025-01-27T15:15:13.607

Modified: 2026-06-17T08:59:11.610

Link: CVE-2025-24538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:30:20Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)