CVE-2017-6954

MEDIUM4.3EPSS 0.29%

BuddyPress Docs plugin Improper Privilege Management

Published: 5/13/2022Modified: 4/25/2024
Also known as:GHSA-9wf6-88x4-6xvj

Description

An issue was discovered in `includes/component.php` in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

References (4)