CVE-2025-5526

Publication date

2025-06-27 06:00:11

Family

WPScan

State

PUBLISHED

Description

The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user