Missing Authorization in WP Docs by Fahad Mahmood
CVE-2026-24990
5.4MEDIUM
What is CVE-2026-24990?
The WP Docs plugin developed by Fahad Mahmood contains a missing authorization vulnerability that could lead to unauthorized access due to incorrectly configured security levels. This flaw enables attackers to bypass access restrictions, compromising sensitive files and potentially exposing confidential information. Affected versions include WP Docs up to and including 2.2.8. It is essential for users to ensure that they are running an updated version to protect against this vulnerability.
Affected Version(s)
WP Docs 0 <= 2.2.8