WordPress Plugin Vulnerabilities

BuddyPress Docs < 2.2.5 - Subscriber+ Arbitrary Document Read/Update

Description

The plugin lacks proper access controls and allows a logged in user to view and download files belonging to another user

Proof of Concept

Affects Plugins

Fixed in 2.2.5

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Terrence Bosco, Alexus Bosco, Andrew Risorto
Submitter
Terrence Bosco, Alexus Bosco, Andrew Risorto
Verified
Yes

Timeline

Publicly Published
2025-06-06 (about 7 months ago)
Added
2025-06-06 (about 7 months ago)
Last Updated
2025-06-06 (about 7 months ago)

Other