Description
WordPress Plugin BP Group Documents is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently edit any document. WordPress Plugin BP Group Documents version 1.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.11 or latest
References
Related Vulnerabilities
WordPress Plugin Storefront Footer Text Cross-Site Scripting (1.0.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0124)
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23618)
WordPress Plugin kk Star Ratings 'root' Parameter Remote File Include (1.7)