The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another userCreditsTerrence BoscoAlexus BoscoAndrew RisortoWPScanReferenceshttps://wpscan.com/vulnerability/10196cd3-5bf7-4e40-a4f7-4ff2d34d516d/