Access violation vulnerability in BP Group Documents 1.2.1

The Group Documents plugin for WordPress, up to version 1.2.1, contains a vulnerability that could be exploited by unauthenticated attackers. This vulnerability allows them to change the location of any file that the compromised user has access to in the upload directories. This is done by exploiting the Path Traversal vulnerability found in the bp-group-documents-settings.php file.

Detected in:

BP Group Documents fixed vulnerable versions: >= * <= 1.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.