Unauthorized Data Access in BetterDocs Documentation Plugin for WordPress
CVE-2025-7499

5.3MEDIUM

What is CVE-2025-7499?

The BetterDocs plugin for WordPress, utilized for advanced documentation and FAQ functionalities, is susceptible to unauthorized data access. A flaw in the get_response function allows attackers to access sensitive information without authentication. This vulnerability impacts all versions up to 4.1.1, enabling potential intruders to retrieve passwords for protected documents, along with metadata concerning private and draft documents. Users should promptly update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers * <= 4.1.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaditya Banwari
.
CVE-2025-7499 : Unauthorized Data Access in BetterDocs Documentation Plugin for WordPress