CVE Database /
CVE-2017-6954
CVE · Medium
CVE-2017-6954 — BuddyPress Docs [buddypress-docs] < 1.9.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-6954
|
BuddyPress Docs [buddypress-docs] < 1.9.3 |
Improper Privilege Management |
Medium
4.3
|
< 1.9.3
|
1.9.3 |
2017-03-17 |
—
|
CVE-2017-6954
The BuddyPress Docs plugin versions prior to 1.9.3 contain a flaw in the includes/component.php file that allows logged-in users to modify documents belonging to other users by circumventing authorization checks. This vulnerability affects any authenticated user on the site, regardless of their intended access level to specific documents. The issue was resolved in version 1.9.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings