plugin

Betterdocs Vulnerabilities

25 known security issues reported for the Betterdocs WordPress plugin. Most recent disclosed Jul 24, 2026.

1 critical 2 high 11 medium

Running Betterdocs on your site? Check whether your installed version is affected.

Scan your site free

BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.4
Affected:
up to 4.6.2
Fixed in:
4.7.0
Disclosed:
Jul 24, 2026

CVE-2026-65562 on NVD →

BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter

medium

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...

CVSS:
6.5
Affected:
up to 4.6.0
Fixed in:
4.6.1
Disclosed:
Jul 9, 2026

CVE-2026-15104 on NVD →

BetterDocs <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting

high

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
Jun 25, 2026

CVE-2026-11371 on NVD →

BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute

medium

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and...

CVSS:
6.4
Affected:
up to 4.5.3
Fixed in:
4.5.4
Disclosed:
Jun 18, 2026

CVE-2026-12157 on NVD →

BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage

medium

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for authenticated...

CVSS:
4.3
Affected:
up to 4.3.11
Fixed in:
4.3.12
Disclosed:
Apr 23, 2026

CVE-2026-6393 on NVD →

BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 4.3.8
Fixed in:
4.3.9
Disclosed:
Apr 15, 2026

CVE-2026-3875 on NVD →

BetterDocs <= 4.3.10 - Unauthenticated Information Exposure

medium

The BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.10. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.3.10
Fixed in:
4.3.11
Disclosed:
Mar 18, 2026

CVE-2026-42644 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 4.3.4

unknown

[en] The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in p...

Affected:
up to 4.3.4
Fixed in:
4.3.4
Disclosed:
Jan 9, 2026

CVE-2025-14980 on NVD →

BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure

medium

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin...

CVSS:
6.5
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Jan 8, 2026

CVE-2025-14980 on NVD →

BetterDocs <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure

medium

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1...

CVSS:
5.3
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Aug 15, 2025

CVE-2025-7499 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 2.5.3

unknown

[en] Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through 2.5.2.

Affected:
up to 2.5.3
Fixed in:
2.5.3
Disclosed:
Dec 9, 2024

CVE-2023-47762 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 3.5.9

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.

Affected:
up to 3.5.9
Fixed in:
3.5.9
Disclosed:
Aug 13, 2024

CVE-2024-43129 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 3.5.9

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.

Affected:
up to 3.5.9
Fixed in:
3.5.9
Disclosed:
Aug 12, 2024

CVE-2024-43227 on NVD →

BetterDocs <= 3.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via blocks in versions up to, and including, 3.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inje...

CVSS:
6.4
Affected:
up to 3.5.8
Fixed in:
3.5.9
Disclosed:
Aug 9, 2024

CVE-2024-43227 on NVD →

BetterDocs <= 3.5.8 - Authenticated (Contributor+) Local File Inclusion

high

The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.5.8 via the 'layout_template' of several blocks. This makes it possible for authenticated attacke...

CVSS:
8.8
Affected:
up to 3.5.8
Fixed in:
3.5.9
Disclosed:
Aug 7, 2024

CVE-2024-43129 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 3.5.0

unknown

[en] The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output e...

Affected:
up to 3.5.0
Fixed in:
3.5.0
Disclosed:
Apr 9, 2024

CVE-2024-2845 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 3.3.4

unknown

[en] Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.

Affected:
up to 3.3.4
Fixed in:
3.3.4
Disclosed:
Mar 28, 2024

CVE-2024-30226 on NVD →

BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg <= 3.3.3 - Unauthenticated PHP Object Injection

critical

The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via...

CVSS:
9.8
Affected:
up to 3.3.3
Fixed in:
3.3.4
Disclosed:
Mar 26, 2024

CVE-2024-30226 on NVD →

BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escapi...

CVSS:
6.4
Affected:
up to 3.4.2
Fixed in:
3.5.0
Disclosed:
Mar 25, 2024

CVE-2024-2845 on NVD →

BetterDocs <= 2.5.2 - Missing Authorization via AJAX actions

medium

The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability check on several AJAX functions in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify documents.

CVSS:
4.3
Affected:
up to 2.5.2
Fixed in:
2.5.3
Disclosed:
Nov 13, 2023

CVE-2023-47762 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 1.9.2

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.9.1).

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Sep 20, 2021

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 1.9.0

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.8.4).

Affected:
up to 1.9.0
Fixed in:
1.9.0
Disclosed:
Sep 10, 2021

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 4.1.2

unknown
Affected:
up to 4.1.2
Fixed in:
4.1.2

CVE-2025-7499 on NVD →

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] >= 1.9.0 - <= 1.9.1

unknown

The plugin does not escape the date_range parameter before outputting it back in the All docs admin dashboard, leading to a Reflected Cross-Site Scripting issue

Affected:
1.9.0 – 1.9.1
Fixed in:
1.9.1

BetterDocs – Knowledge Base Documentation &amp; FAQ Solution for Elementor &amp; Block Editor [betterdocs] < 1.9.0

unknown

The plugin does not escape the tag_ID before outputting it back in the edit category page of the admin dashboard, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.9.0
Fixed in:
1.9.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database