Extension WordPress

Vulnérabilités BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

Cette page rassemble les failles publiées pour BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
1Critiques
12Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

12 fiches

CVE-2026-15104 Moyenne · 6,5
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.6.0 – Authenticated (Custom+) SQL Injection via 'lang' Parameter

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on…

Versions affectées

*-4.6.0

Correctif

4.6.1

Publication

09/07/2026

CVE-2026-12157 Moyenne · 6,4
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute

The BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including,…

Versions affectées

*-4.5.3

Correctif

4.5.4

Publication

18/06/2026

CVE-2026-6393 Moyenne · 4,3
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.3.11 – Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check in the generate_openai_content_callback() function, which relies solely on a nonce rather than verifying…

Versions affectées

*-4.3.11

Correctif

4.3.12

Publication

23/04/2026

CVE-2026-3875 Moyenne · 6,4
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.3.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shortcode in all versions up to, and including, 4.3.8. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes.…

Versions affectées

*-4.3.8

Correctif

4.3.9

Publication

15/04/2026

CVE-2026-42644 Moyenne · 5,3
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.3.10 – Unauthenticated Information Exposure

The BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.10. This makes it possible for unauthenticated attackers…

Versions affectées

*-4.3.10

Correctif

4.3.11

Publication

18/03/2026

CVE-2025-14980 Moyenne · 6,5
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.3.3 – Authenticated (Contributor+) Sensitive Information Exposure

The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive…

Versions affectées

*-4.3.3

Correctif

4.3.4

Publication

08/01/2026

CVE-2025-7499 Moyenne · 5,3
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 4.1.1 – Missing Authorization to Private And Password-Protected Posts Information Disclosure

The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on…

Versions affectées

*-4.1.1

Correctif

4.1.2

Publication

15/08/2025

CVE-2024-43227 Moyenne · 6,4
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 3.5.8 – Authenticated (Contributor+) Stored Cross-Site Scripting

The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via blocks in versions up to, and including, 3.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

Versions affectées

*-3.5.8

Correctif

3.5.9

Publication

09/08/2024

CVE-2024-43129 Élevée · 8,8
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 3.5.8 – Authenticated (Contributor+) Local File Inclusion

The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.5.8 via…

Versions affectées

*-3.5.8

Correctif

3.5.9

Publication

07/08/2024

CVE-2024-30226 Critique · 9,8
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg <= 3.3.3 – Unauthenticated PHP Object Injection

The BetterDocs plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.3 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known…

Versions affectées

*-3.3.3

Correctif

3.3.4

Publication

26/03/2024

CVE-2024-2845 Moyenne · 6,4
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to,…

Versions affectées

*-3.4.2

Correctif

3.5.0

Publication

25/03/2024

CVE-2023-47762 Moyenne · 4,3
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

BetterDocs <= 2.5.2 – Missing Authorization via AJAX actions

The BetterDocs plugin for WordPress is vulnerable to unauthorized document modification due to a missing capability check on several AJAX functions in versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with subscriber-level access…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

13/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités