CVE-2017-6954

MEDIUM

BuddyPress Docs <1.9.3 - Privilege Escalation

Title source: llm

Description

An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.

Scores

CVSS v3 4.3
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-269
Status published

Affected Products (3)

buddypress/buddypress < 1.9.2
buddypress/buddypress < 1.9.3Packagist
n/a/n/a

Timeline

Published Mar 17, 2017
Tracked Since Feb 18, 2026