Description
The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 2.2.5
Credits
Terrence Bosco
Alexus Bosco
Andrew Risorto
WPScan
References
wpscan.com/...rability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/
wpscan.com/...rability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/