CVE-2017-6954: Medium severity BuddyPress BuddyPress vulnerability
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.
Other sources
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/buddypress/buddypressto a version that resolves this vulnerability.Fixed in 1.9.3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6954?
CVE-2017-6954 has a medium severity rating due to the possibility of authenticated users editing documents of others without proper permissions.
How do I fix CVE-2017-6954?
To fix CVE-2017-6954, update the BuddyPress Docs plugin to version 1.9.3 or later.
Who is affected by CVE-2017-6954?
Users of the BuddyPress Docs plugin version 1.9.2 and earlier on WordPress are affected by CVE-2017-6954.
What kind of vulnerability is CVE-2017-6954?
CVE-2017-6954 is a privilege escalation vulnerability that allows unauthorized document edits by authenticated users.
When was CVE-2017-6954 disclosed?
CVE-2017-6954 was disclosed in early 2017, highlighting a security issue in the BuddyPress Docs plugin.