BuddyPress Docs
BuddyPress Docs has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.1 out of 10.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Improper Privilege Management.
Every one of the 3 issues recorded for BuddyPress Docs has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. BuddyPress Docs is installed on roughly 6,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-9207BuddyPress Docs <= 2.2.3 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
BuddyPress Docs
Author
Boone Gorges
BuddyPress Docs adds collaborative work spaces to your BuddyPress community. Part wiki, part document editing, part shared dropbox, think of these Docs as a BuddyPress version of the Docs service offered by the Big G ifyouknowwhatimean Features include: Docs that can be linked to groups or users, with a variety of privacy levels Support for fully-private document uploads Doc taxonomy, using tags Fully sortable and filterable doc lists TinyMCE front-end doc editing One-editor-at-a-time prevention against overwrites, plus idle detection/autosave Full access to revision history Dashboard access and management of Docs for the site admin This plugin is in active development. For feature requests and bug reports, visit http://github.com/boonebgorges/buddypress-docs. If you have translated the plugin and would like to provide your translation for distribution with BuddyPress Docs, please contact the plugin author.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C