plugin

Eazydocs Vulnerabilities

22 known security issues reported for the Eazydocs WordPress plugin. Most recent disclosed Apr 30, 2026.

2 high 9 medium

Running Eazydocs on your site? Check whether your installed version is affected.

Scan your site free

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.5.7
Fixed in:
2.5.9
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] <= 2.6.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in Spider Themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EazyDocs: from n/a through 2.6.4.

Affected:
up to 2.6.4
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-32221 on NVD →

EazyDocs <= 2.7.1 - Missing Authorization

medium

The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

CVSS:
4.3
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Apr 7, 2025

CVE-2025-32221 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.3.6

unknown

[en] Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.3.5.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Jan 2, 2025

CVE-2023-47648 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] <= 2.6.4 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.

Affected:
up to 2.6.4
Fix:
No patched version reported
Disclosed:
Dec 16, 2024

CVE-2024-54376 on NVD →

EazyDocs <= 2.8.0 - Authenticated (Contributor+) Local File Inclusion

high

The EazyDocs plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.8.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
8.8
Affected:
up to 2.8.0
Fixed in:
2.8.1
Disclosed:
Dec 11, 2024

CVE-2024-54376 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.5.1

unknown

[en] Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.5.0.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Nov 1, 2024

CVE-2024-38721 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.5.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EazyDocs eazydocs allows Stored XSS.This issue affects EazyDocs: from n/a through 2.5.0.

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Jul 20, 2024

CVE-2024-38720 on NVD →

EazyDocs <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The EazyDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jul 11, 2024

CVE-2024-38720 on NVD →

EazyDocs <= 2.5.0 - Missing Authorization

medium

The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

CVSS:
4.3
Affected:
up to 2.5.0
Fixed in:
2.5.1
Disclosed:
Jul 11, 2024

CVE-2024-38721 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.5.0

unknown

[en] The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Jul 2, 2024

CVE-2024-3999 on NVD →

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin <= 2.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
4.4
Affected:
up to 2.4.1
Fixed in:
2.5.0
Disclosed:
Jun 11, 2024

CVE-2024-3999 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.4.0

unknown

[en] The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2....

Affected:
up to 2.4.0
Fixed in:
2.4.0
Disclosed:
Feb 12, 2024

CVE-2024-0248 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.3.6

unknown

[en] The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Jan 15, 2024

CVE-2023-6029 on NVD →

EazyDocs 2.3.8 - 2.3.9 - Missing Authorization

medium

The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on various functions in versions 2.3.8 to 2.3.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts and add/delete documents and secti...

CVSS:
4.3
Affected:
2.3.8 – 2.3.9
Fixed in:
2.4.0
Disclosed:
Dec 21, 2023

CVE-2024-0248 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.3.4

unknown

[en] The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Dec 11, 2023

CVE-2023-6035 on NVD →

EazyDocs <= 2.3.3 - Authenticated (Subscriber+) SQL Injection

high

The EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) plugin for WordPress is vulnerable to SQL Injection via the 'data' parameter in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati...

CVSS:
8.8
Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Nov 20, 2023

CVE-2023-6035 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.3.6

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Nov 14, 2023

CVE-2023-47549 on NVD →

EazyDocs <= 2.3.5 - Missing Authorization via doc_one_page and edit_doc_one_page

medium

The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the doc_one_page and edit_doc_one_page functions in versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to publish and edit the plugin's OnePage document. CVE-...

CVSS:
6.5
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Nov 7, 2023

CVE-2023-47648 on NVD →

EazyDocs <= 2.3.5 - Unauthenticated Stored Cross-Site Scripting via edit_doc_one_page

medium

The EazyDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘edit_doc_one_page’ parameter in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.1
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Nov 7, 2023

CVE-2023-47549 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

EazyDocs &#8211; Easy Knowledge Base, Wiki, and Documentation Builder [eazydocs] < 2.2.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.2.1
Fixed in:
2.2.1

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database