BP Group Documents

BP Group Documents has 4 disclosed vulnerabilities in the WordSec catalog, all reported in 2013; all 4 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2013 was the busiest year with 4 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Path Traversal.

Every one of the 4 issues recorded for BP Group Documents has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Mallory Adams. BP Group Documents is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

4

Get automatic notifications for all BP Group Documents vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8

BP Group Documents <= 1.2.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

4 records
Plugin Profile
Latestv2.1

BP Group Documents

lenasterg

Author

lenasterg

5.0(15)
100/100
Last Updated
2025-07-10 (1y ago)
Active Installs
600+
Downloads
64,480
Requires WP
4.6+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2013-08-30 (13y ago)
Requires Plugins
buddypress

BP Group Documents creates a page within each BuddyPress group to upload and any type of file or document. This allows members of BuddyPress groups to upload and store files and documents that are relevant to the group. Documents can be edited and deleted either by the document owner or by the group administrator. Categories can be used to organize documents. Activity is logged in the main activity stream, and is also tied to the user and group activity streams. The site administrator can set filters on file extensions, set display options. Group members and moderators can receive email notifications at their option. The group administrator can decide if all members or only admins/moderators can upload documents (Since v0.5) User verification for Downloads: when a document is downloaded, a redirect page checks is the user is member of the group (in case of a private or hidden groups) and only then the user can download the file.(Since v0.5) For private networks, see the FAQ “I have a members only network. How to disable file download for non members?” . 4 Widgets: “User’s groups documents”, “Recent Uploads” , “Popular Downloads”, can be used to show activity at a glance. If the theme support different sidebars for group pages, the BP_Group_Documents_CurrentGroup_Widget can be used to show current group’s documents. Contributions by Lena Stergatou, with additional bug fixes and improvements by Keeble Smith (http://keeblesmith.com) and Anton Andreasson work for BP 1.7. Original plugin author was Peter Anselmo. PLEASE: If you have any issues or it doesn’t work for you, please report in support forum. It doesn’t help anyone to mark “broken” without asking around. Thanks! Notes Roadmap.txt – contains ideas proposed and the (approximate) order of implementation History.txt – contains all the changes since version .1 License.txt – contains the licensing details for this component.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C