First published: Fri Mar 17 2017(Updated: )
An issue was discovered in `includes/component.php` in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/buddypress/buddypress | <1.9.3 | 1.9.3 |
BuddyPress | <=1.9.2 |
https://github.com/boonebgorges/buddypress-docs/commit/75293ed4e5f31f04e54689bfe2c647e3e3f5e1a9
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6954 has a medium severity rating due to the possibility of authenticated users editing documents of others without proper permissions.
To fix CVE-2017-6954, update the BuddyPress Docs plugin to version 1.9.3 or later.
Users of the BuddyPress Docs plugin version 1.9.2 and earlier on WordPress are affected by CVE-2017-6954.
CVE-2017-6954 is a privilege escalation vulnerability that allows unauthorized document edits by authenticated users.
CVE-2017-6954 was disclosed in early 2017, highlighting a security issue in the BuddyPress Docs plugin.