CVE-2025-5526: BuddyPress Docs < 2.2.5 - Subscriber+ Arbitrary Document Read/Update
Published Jun 27, 2025
·Updated
The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
Affected Software
2 affected components
BuddyPress BuddyPress Docs<2.2.5
Boonebgorges Buddypress Docs Wordpress<2.2.5
Event History
Jun 27, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5526?
CVE-2025-5526 is considered a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2025-5526?
To fix CVE-2025-5526, update the BuddyPress Docs plugin to version 2.2.5 or later.
3
What type of vulnerability is CVE-2025-5526?
CVE-2025-5526 is an access control vulnerability that allows users to view and download files from other users.
4
Who is affected by CVE-2025-5526?
Users of the BuddyPress Docs WordPress plugin prior to version 2.2.5 are affected by CVE-2025-5526.
5
What can attackers do with CVE-2025-5526?
Attackers can exploit CVE-2025-5526 to gain unauthorized access to and download files that belong to other users.