BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
critical
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 9.8
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Jun 18, 2026
CVE-2026-7515 on NVD →
BetterDocs Pro <= 3.7.0 - Unauthenticated SQL Injection via Encyclopedia 'limit' Parameter
high
The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_by_letter` AJAX actions in all versions up to, and including, 3.7.0. This is due to the `limit` POST parameter being interpolated directly into a SQL query string before being passed to `$wpdb->prepar...
- CVSS:
- 7.5
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1
- Disclosed:
- May 6, 2026
CVE-2026-4348 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database