The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Metrics
Affected Vendors & Products
References
History
Fri, 27 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user | |
Title | BuddyPress Docs < 2.2.5 - Subscriber+ Arbitrary Document Read/Update | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-06-27T06:00:11.971Z
Updated: 2025-06-27T06:00:11.971Z
Reserved: 2025-06-03T13:03:21.291Z
Link: CVE-2025-5526

No data.

Status : Awaiting Analysis
Published: 2025-06-27T06:15:26.763
Modified: 2025-06-30T18:38:48.477
Link: CVE-2025-5526

No data.