BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 4.6.2
- Fixed in:
- 4.7.0
- Disclosed:
- Jul 24, 2026
CVE-2026-65562 on NVD →
BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter
medium
The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...
- CVSS:
- 6.5
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.1
- Disclosed:
- Jul 9, 2026
CVE-2026-15104 on NVD →
BetterDocs <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting
high
The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- Jun 25, 2026
CVE-2026-11371 on NVD →
BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute
medium
The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and...
- CVSS:
- 6.4
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.4
- Disclosed:
- Jun 18, 2026
CVE-2026-12157 on NVD →
BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage
medium
The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying user permissions. This makes it possible for authenticated...
- CVSS:
- 4.3
- Affected:
- up to 4.3.11
- Fixed in:
- 4.3.12
- Disclosed:
- Apr 23, 2026
CVE-2026-6393 on NVD →
BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 4.3.8
- Fixed in:
- 4.3.9
- Disclosed:
- Apr 15, 2026
CVE-2026-3875 on NVD →
BetterDocs <= 4.3.10 - Unauthenticated Information Exposure
medium
The BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.10. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.3.10
- Fixed in:
- 4.3.11
- Disclosed:
- Mar 18, 2026
CVE-2026-42644 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 4.3.4
unknown
[en] The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in p...
- Affected:
- up to 4.3.4
- Fixed in:
- 4.3.4
- Disclosed:
- Jan 9, 2026
CVE-2025-14980 on NVD →
BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure
medium
The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin...
- CVSS:
- 6.5
- Affected:
- up to 4.3.3
- Fixed in:
- 4.3.4
- Disclosed:
- Jan 8, 2026
CVE-2025-14980 on NVD →
BetterDocs <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure
medium
The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_response function in all versions up to and including 4.1.1...
- CVSS:
- 5.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Aug 15, 2025
CVE-2025-7499 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 2.5.3
unknown
[en] Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through 2.5.2.
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.3
- Disclosed:
- Dec 9, 2024
CVE-2023-47762 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 3.5.9
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.
- Affected:
- up to 3.5.9
- Fixed in:
- 3.5.9
- Disclosed:
- Aug 13, 2024
CVE-2024-43129 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 3.5.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.
- Affected:
- up to 3.5.9
- Fixed in:
- 3.5.9
- Disclosed:
- Aug 12, 2024
CVE-2024-43227 on NVD →
BetterDocs <= 3.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via blocks in versions up to, and including, 3.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inje...
- CVSS:
- 6.4
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.9
- Disclosed:
- Aug 9, 2024
CVE-2024-43227 on NVD →
BetterDocs <= 3.5.8 - Authenticated (Contributor+) Local File Inclusion
high
The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.5.8 via the 'layout_template' of several blocks. This makes it possible for authenticated attacke...
- CVSS:
- 8.8
- Affected:
- up to 3.5.8
- Fixed in:
- 3.5.9
- Disclosed:
- Aug 7, 2024
CVE-2024-43129 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 3.5.0
unknown
[en] The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output e...
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Apr 9, 2024
CVE-2024-2845 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 3.3.4
unknown
[en] Deserialization of Untrusted Data vulnerability in WPDeveloper BetterDocs.This issue affects BetterDocs: from n/a through 3.3.3.
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Mar 28, 2024
CVE-2024-30226 on NVD →
BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg <= 3.3.3 - Unauthenticated PHP Object Injection
critical
The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via...
- CVSS:
- 9.8
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.4
- Disclosed:
- Mar 26, 2024
CVE-2024-30226 on NVD →
BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escapi...
- CVSS:
- 6.4
- Affected:
- up to 3.4.2
- Fixed in:
- 3.5.0
- Disclosed:
- Mar 25, 2024
CVE-2024-2845 on NVD →
BetterDocs <= 2.5.2 - Missing Authorization via AJAX actions
medium
The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability check on several AJAX functions in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify documents.
- CVSS:
- 4.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Nov 13, 2023
CVE-2023-47762 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 1.9.2
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.9.1).
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Sep 20, 2021
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 1.9.0
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress BetterDocs plugin (versions <= 1.8.4).
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- Sep 10, 2021
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 4.1.2
unknown
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
CVE-2025-7499 on NVD →
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] >= 1.9.0 - <= 1.9.1
unknown
The plugin does not escape the date_range parameter before outputting it back in the All docs admin dashboard, leading to a Reflected Cross-Site Scripting issue
- Affected:
- 1.9.0 – 1.9.1
- Fixed in:
- 1.9.1
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor [betterdocs] < 1.9.0
unknown
The plugin does not escape the tag_ID before outputting it back in the edit category page of the admin dashboard, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database