The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Boonebgorges
Boonebgorges buddypress Docs
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:boonebgorges:buddypress_docs:*:*:*:*:*:wordpress:*:*
Vendors & Products Boonebgorges
Boonebgorges buddypress Docs

Tue, 01 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Title BuddyPress Docs < 2.2.5 - Subscriber+ Arbitrary Document Read/Update
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-07-01T19:19:08.270Z

Reserved: 2025-06-03T13:03:21.291Z

Link: CVE-2025-5526

cve-icon Vulnrichment

Updated: 2025-07-01T19:18:59.814Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-27T06:15:26.763

Modified: 2025-07-03T16:56:52.057

Link: CVE-2025-5526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.