CVE-2017-6954: Buddypress
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.
Affected products
- Buddypress Buddypress: up to and including 1.9.2
Published 2017-03-17. Last modified 2026-06-17.