PT-2026-38341 · WordPress · Betterdocs Pro
Published
2026-05-07
·
Updated
2026-05-07
·
CVE-2026-4348
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BetterDocs Pro versions prior to 3.7.1
Description
The plugin is susceptible to SQL Injection through the
get current letter docs and docs sort by letter AJAX actions. The issue occurs because the limit POST parameter is interpolated directly into a SQL query string before being processed by $wpdb->prepare(), which fails to parameterize this specific variable. This allows unauthenticated attackers to append malicious SQL queries to extract sensitive information from the database. This issue is exploitable only if the Encyclopedia feature is enabled in the settings.Recommendations
Update to a version later than 3.7.0.
As a temporary mitigation, disable the Encyclopedia feature in the settings to prevent exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Betterdocs Pro