CVE-2025-5526

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Configurations

Configuration 1 (hide)

cpe:2.3:a:boonebgorges:buddypress_docs:*:*:*:*:*:wordpress:*:*

History

03 Jul 2025, 16:56

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/ - () https://wpscan.com/vulnerability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/ - Exploit, Third Party Advisory
First Time Boonebgorges buddypress Docs
Boonebgorges
CPE cpe:2.3:a:boonebgorges:buddypress_docs:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo

01 Jul 2025, 20:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/ - () https://wpscan.com/vulnerability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

30 Jun 2025, 18:38

Type Values Removed Values Added
Summary
  • (es) El complemento BuddyPress Docs para WordPress anterior a la versión 2.2.5 carece de controles de acceso adecuados y permite que un usuario que haya iniciado sesión vea y descargue archivos que pertenecen a otro usuario.

27 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-27 06:15

Updated : 2025-07-03 16:56


NVD link : CVE-2025-5526

Mitre link : CVE-2025-5526

CVE.ORG link : CVE-2025-5526


JSON object : View

Products Affected

boonebgorges

  • buddypress_docs