PT-2026-1762 · WordPress · Betterdocs
Dmitry Ignatyev
·
Publicado
2026-01-09
·
Atualizado
2026-01-09
·
CVE-2025-14980
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BetterDocs versions prior to 4.3.4
Description
The BetterDocs plugin for WordPress is susceptible to sensitive information exposure through the
scripts() function. Authenticated attackers with contributor-level access or higher can potentially extract sensitive data, including the OpenAI API key stored in the plugin settings.Recommendations
Update BetterDocs to version 4.3.4 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Betterdocs