CVE-2017-6954: Buddypress

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.

Affected products

Published 2017-03-17. Last modified 2026-06-17.