{"error":0,"message":null,"data":{"name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot","plugin":"betterdocs","link":"https:\/\/wordpress.org\/plugins\/betterdocs\/","latest":"1789536900","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"4f08acecfbd3cddf83f7df1c32cdc7a8dd5a04d23b4b8432d12cfe29dd573005","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 1.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"570a5ea4283ba5eedfe576e20fa6580f667ce12b","name":"WordPress BetterDocs plugin <= 1.9.1 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-1-9-1-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.9.1).","date":"2021-09-20"}],"impact":[]},{"uuid":"75252bcab3a74c4a880f7820510d757c47c0c93edc3b5acbe03936e52a7d186b","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 1.9.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d82c57693fa37786130fe02fd3cfd7b31e04b599","name":"WordPress BetterDocs plugin <= 1.8.4 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-1-8-4-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.8.4).","date":"2021-09-10"}],"impact":[]},{"uuid":"b9e5bde1c10da63b0bd5952f082fdf10b87f753398d07f2f0fe306bc88910b54","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 1.9.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"396124e9-d6ef-46dd-a245-39db39054e51","name":"BetterDocs &lt; 1.9.0 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/396124e9-d6ef-46dd-a245-39db39054e51","description":"The plugin does not escape the tag_ID before outputting it back in the edit category page of the admin dashboard, leading to a Reflected Cross-Site Scripting issue","date":null}],"impact":[]},{"uuid":"5b9f6743dd8f6a508706178ef162d560bdf9c300e71aef5f8c8c23b73746f783","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] >= 1.9.0 - <= 1.9.1","description":null,"operator":{"min_version":"1.9.0","min_operator":"ge","max_version":"1.9.1","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"5aee3b0b-3c93-4b18-86d4-ee1634d37dd1","name":"BetterDocs 1.9.0-1.9.1 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/5aee3b0b-3c93-4b18-86d4-ee1634d37dd1","description":"The plugin does not escape the date_range parameter before outputting it back in the All docs admin dashboard, leading to a Reflected Cross-Site Scripting issue","date":null}],"impact":[]},{"uuid":"f0c6dcf55b04d08cda9df1c3b777892cf08e86d34fe582d2596db7ff4777c9f4","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 2.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-47762","name":"CVE-2023-47762","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-47762","description":"[en] Missing Authorization vulnerability in WPDeveloper BetterDocs betterdocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n\/a through <= 2.5.2.","date":"2024-12-09"},{"id":"2e629597c453293e83fe2b295427205e9d9e317e","name":"WordPress  BetterDocs Plugin  <= 2.5.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-2-5-2-broken-access-control-vulnerability","description":"Update the WordPress BetterDocs plugin to the latest available version (at least 2.5.3).\nAbdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress BetterDocs Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.5.3.","date":"2023-11-13"},{"id":"6f510548a7ce345a7bb3844a9c911ed04afd80af","name":"BetterDocs <= 2.5.2 - Missing Authorization via AJAX actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-252-missing-authorization-via-ajax-actions","description":"The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability check on several AJAX functions in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify documents.","date":"2023-11-13"},{"id":"4a94ca48-09d3-47b1-8377-66e1ea5ea174","name":"BetterDocs &lt; 2.5.3 - Missing Authorization via AJAX actions","link":"https:\/\/wpscan.com\/vulnerability\/4a94ca48-09d3-47b1-8377-66e1ea5ea174","description":"The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability check on several AJAX functions in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify documents.","date":null},{"id":"EUVD-2023-51860","name":"EUVD-2023-51860","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-51860","description":"Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n\/a through 2.5.2.","date":"2024-12-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"c537b97aed0e88b38af65100d07b76de10364cb3fd8e2ab64a5d241c12c72eea","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 3.5.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2845","name":"CVE-2024-2845","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2845","description":"[en] The BetterDocs \u2013 Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"a844b6a4a2b439c1e2942d5df4880fe8e9c23f83","name":"BetterDocs \u2013 Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-best-documentation-faq-knowledge-base-plugin-with-ai-support-instant-answer-for-elementor-gutenberg-342-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The BetterDocs \u2013 Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-25"},{"id":"33ccd33756718b1470aa81713938cb96ef362891","name":"WordPress  BetterDocs Plugin    <= 3.4.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-3-4-2-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress BetterDocs plugin to the latest available version (at least 3.5.0).\nKrzysztof Zaj\u0105c discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress BetterDocs Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.5.0.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"7ec56e5f-0ddf-4425-8a8f-7d56ff4754fa","name":"BetterDocs &ndash; Best Documentation, FAQ &amp; Knowledge Base Plugin with AI Support &amp; Instant Answer For Elementor &amp; Gutenberg &lt; 3.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/7ec56e5f-0ddf-4425-8a8f-7d56ff4754fa","description":"The BetterDocs &ndash; Best Documentation, FAQ &amp; Knowledge Base Plugin with AI Support &amp; Instant Answer For Elementor &amp; Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7cf57bd0d8f3bbb732f59ddb44aefeeb3e1f99aa6549dd0285a28478199b5b7e","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 3.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-30226","name":"CVE-2024-30226","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-30226","description":"[en] Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n\/a through 3.3.3.","date":"2024-03-28"},{"id":"bf6f3139e8759e0e2dd2a9ff69f09a338eb4b3f0","name":"WordPress  BetterDocs Plugin    <= 3.3.3 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-3-3-3-unauthenticated-php-object-injection-vulnerability","description":"Update the WordPress BetterDocs plugin to the latest available version (at least 3.3.4).\nstealthcopter discovered and reported this PHP Object Injection vulnerability in WordPress BetterDocs Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 3.3.4.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"84dcb3027f7b170480020b71dd1fcdc21ff9e57c","name":"BetterDocs \u2013 Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg <= 3.3.3 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/UNKNOWN-CVE-2024-30226-1\/betterdocs-best-documentation-faq-knowledge-base-plugin-with-ai-support-instant-answer-for-elementor-gutenberg-333-unauthenticated-php-object-injection","description":"The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-03-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.0","severity":"c","exploitable":"2.2","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.0","severity":"critical","av":"network","ac":"high","pr":"none","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"6.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"efcd5e9d3d79d8d0699e7d4fa549e92ddf99c58f4b4066f3605054365b7596e5","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 3.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43129","name":"CVE-2024-43129","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43129","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n\/a through 3.5.8.","date":"2024-08-13"},{"id":"2334b6d39c7e775ac12b077a8be0a7ed27a0054a","name":"WordPress BetterDocs Plugin <= 3.5.8 is vulnerable to Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-3-5-8-local-file-inclusion-vulnerability","description":"<p>WordPress BetterDocs Plugin <= 3.5.8 is vulnerable to Local File Inclusion<\/p><p>Software: BetterDocs<\/p><p>Link: https:\/\/wordpress.org\/plugins\/betterdocs\/#developers<\/p><p>Affected Version <= 3.5.8<\/p><p>Fixed in version 3.5.9 <\/p>","date":"2024-08-07"},{"id":"e3355b3c0ca02ddf7e11c456ed5312a49556a39b","name":"BetterDocs <= 3.5.8 - Authenticated (Contributor+) Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-358-authenticated-contributor-local-file-inclusion","description":"The BetterDocs \u2013 Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.5.8 via the 'layout_template' of several blocks. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2024-08-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e09b2f0073265ab3690190af4ae6b81fffadfd7dc7b3355682ebabec33f930e5","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 3.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43227","name":"CVE-2024-43227","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43227","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n\/a through 3.5.8.","date":"2024-08-12"},{"id":"362f7d1c8fc6ba6ef1e69399c4f7f9e695269813","name":"WordPress BetterDocs Plugin <= 3.5.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-best-documentation-faq-knowledge-base-plugin-with-ai-support-instant-answer-for-elementor-gutenberg-plugin-3-5-8-cross-site-scripting-xss-vulnerability","description":"<p>WordPress BetterDocs Plugin <= 3.5.8 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: BetterDocs<\/p><p>Link: https:\/\/wordpress.org\/plugins\/betterdocs\/#developers<\/p><p>Affected Version <= 3.5.8<\/p><p>Fixed in version 3.5.9 <\/p>","date":"2024-08-09"},{"id":"fff725e863f9b3b6a4f1fc224ec316c47ee42b4e","name":"BetterDocs <= 3.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-358-authenticated-contributor-stored-cross-site-scripting","description":"The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via blocks in versions up to, and including, 3.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f520d967c6f2e7e3896f15da4ca4d12fe11ba1069b70a5b4495aea01c47849b2","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-7499","name":"BetterDocs  <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-7499","description":"The BetterDocs \u2013 Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.","date":"0000-00-00"},{"id":"8d304c28e72c10ac27940da417c00210f37481a9","name":"BetterDocs  <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-411-missing-authorization-to-private-and-password-protected-posts-information-disclosure","description":"The BetterDocs \u2013 Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.","date":"2025-08-15"},{"id":"ba2675f7221d375c9257efe699fa3c13bc139e15","name":"WordPress BetterDocs Plugin <= 4.1.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/betterdocs\/vulnerability\/wordpress-betterdocs-plugin-4-1-1-missing-authorization-to-private-and-password-protected-posts-information-disclosure-vulnerability","description":"<p>WordPress BetterDocs Plugin <= 4.1.1 is vulnerable to Broken Access Control<\/p><p>Software: BetterDocs<\/p><p>Fixed in version 4.1.2 <\/p><p>Affected Version <= 4.1.1<\/p><p>CVE: CVE-2025-7499<\/p>","date":"2025-08-16"},{"id":"EUVD-2025-25137","name":"EUVD-2025-25137","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-25137","description":"The BetterDocs \u2013 Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.","date":"2025-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"40eb892496f59985057a16e84aedd6f2f7c5e2f4571223dcc7219c3b96f341dc","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14980","name":"CVE-2025-14980","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14980","description":"[en] The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.","date":"2026-01-09"},{"id":"e61fbc74ea6c4da88404f771a6f9ff3fe9ff3957","name":"BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-433-authenticated-contributor-sensitive-information-exposure","description":"The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.","date":"2026-01-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"65ef02eff7a73da33e64d011b28a47e6d1d7f77621c36fca171ea06a8953d50e","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.3.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3875","name":"CVE-2026-3875","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3875","description":"[en] The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-04-16"},{"id":"95a8546a64d0550b22e691d4689be3b052e2b792","name":"BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-438-authenticated-contributor-stored-cross-site-scripting-via-shortcode-attributes","description":"The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-04-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e1ab9241596c76b6fb59fd7938699ceaf5a20b776369b1f50fbf7156ac11fe8b","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.3.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6393","name":"CVE-2026-6393","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6393","description":"[en] The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger OpenAI API calls using the site's configured API key with arbitrary user-controlled prompts, leading to unauthorized consumption of the site owner's paid AI API quota.","date":"2026-04-24"},{"id":"f646f0daa44a9a1a1fd165b58cf242d647b15506","name":"BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-4311-missing-authorization-to-authenticated-subscriber-unauthorized-ai-api-usage","description":"The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for authenticated attackers, with subscriber-level access and above, to trigger OpenAI API calls using the site's configured API key with arbitrary user-controlled prompts, leading to unauthorized consumption of the site owner's paid AI API quota.","date":"2026-04-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"89bd7e2fd22587f6e7fcd1dd1cc5ecc9d59f457c44c37a875473155566e1f05e","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.3.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-42644","name":"CVE-2026-42644","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42644","description":"[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n\/a through <= 4.3.10.","date":"2026-04-29"},{"id":"ff12f84d286852450a6bd45826d4fe32e7d4f501","name":"BetterDocs <= 4.3.10 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-4310-unauthenticated-information-exposure","description":"The BetterDocs \u2013  Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.10. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-03-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"96ae0ed54e21785b491cdc024e506562100d3683a662bc0510921514cbdbd02f","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12157","name":"CVE-2026-12157","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12157","description":"[en] The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs\/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and output escaping in the CategorySlateLayout::render() method, which echoes the blockId block attribute directly into an HTML class attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-19"},{"id":"354aa70406778ca14229b5651ad9ef6982e11a51","name":"BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-453-authenticated-contributor-stored-cross-site-scripting-via-blockid-block-attribute","description":"The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs\/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and output escaping in the CategorySlateLayout::render() method, which echoes the blockId block attribute directly into an HTML class attribute without esc_attr(). This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1b127923f75fd06a20316123629ea40084d4d4e63c8b5f8a462109712bba1aa3","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15104","name":"CVE-2026-15104","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15104","description":"[en] The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a supported multilingual plugin (WPML, Polylang, qTranslate, Weglot, or TranslatePress) to be active on the site, as the vulnerable code path is gated by Helper::is_multilingual_active().","date":"2026-07-10"},{"id":"3c8f6e51a2b434ce2cc0d73f48875baa5f2528d8","name":"BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-460-authenticated-custom-sql-injection-via-lang-parameter","description":"The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires a supported multilingual plugin (WPML, Polylang, qTranslate, Weglot, or TranslatePress) to be active on the site, as the vulnerable code path is gated by Helper::is_multilingual_active().","date":"2026-07-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8377c18b1d8d730cb984f5dc339d75b74f11e8106eaa3d4784989291ef61ecbd","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11371","name":"CVE-2026-11371","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11371","description":"[en] The BetterDocs  WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that executes in the browser of any visitor who views the affected page, including administrators.","date":"2026-07-16"},{"id":"5e3792535cbf6043187d9ce9afc61ceaf344a21a","name":"BetterDocs <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-454-unauthenticated-stored-cross-site-scripting","description":"The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-25"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6944d6d2693e6b5598df90b59a06c35b3e0e594ed9588d5c5de5790e8dcc32b0","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-65562","name":"WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65562","description":"Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.","date":"0000-00-00"},{"id":"81d45abccc5d8144cc565a672d94cf66b70c048c","name":"BetterDocs \u2013  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-ai-documentation-knowledge-base-docs-wikis-faq-with-chatbot-462-authenticated-contributor-stored-cross-site-scripting","description":"The BetterDocs \u2013  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-07-24"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cfb28f91229cea7168c36e1469b8fae4ad686aacf586c6a4ae54804626a49298","name":"BetterDocs \u2013 AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ &amp; Chatbot [betterdocs] < 4.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-75980","name":"CVE-2026-75980","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-75980","description":"[en] The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives wp_kses_post because entity-encoded quotes in a heading id attribute are treated as a single legitimate attribute value at save time; the dangerous payload only materialises after process_content_for_toc() calls html_entity_decode() on the stored content and the broken id is extracted by a lazy regex before being echoed unescaped into the Table of Contents output.","date":"2026-09-01"},{"id":"087b7e51465c785e377cff9d6c831a3e1109fd7a","name":"BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/betterdocs\/betterdocs-481-authenticated-contributor-stored-cross-site-scripting-via-heading-id-attribute-in-post-content","description":"The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives wp_kses_post because entity-encoded quotes in a heading id attribute are treated as a single legitimate attribute value at save time; the dangerous payload only materialises after process_content_for_toc() calls html_entity_decode() on the stored content and the broken id is extracted by a lazy regex before being echoed unescaped into the Table of Contents output.","date":"2026-07-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1788423249"}