Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2025-07-03
CVE-2025-5526 - Buddypress Docs Plugin
The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user
PLUGIN
Buddypress Docs
CVE-2025-5526
Risk Score
Threat Entry
Updated 2024-10-10
CVE-2024-9207 - Buddypress Docs Plugin
The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
PLUGIN
Buddypress Docs
CVE-2024-9207
Risk Score
