Description
Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < 2.2.7.
Published: 2025-03-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the WP Docs plugin, allowing unauthorized users to obtain access to areas of the website that are intended to be controlled, such as documentation pages marked as private or restricted by the site owner. The flaw could enable a threat actor to read confidential documents, modify content, or perform other privileged actions if the plugin lacks proper permissions checks. Because the exploit does not require authentication, it threatens the confidentiality and integrity of the site’s documentation resources.

Affected Systems

Vendor: Fahad Mahmood; Product: WP Docs plugin for WordPress. Versions impacted include all releases prior to 2.2.7; any installation with a version number lower than 2.2.7 or an unknown version is considered vulnerable until upgraded. No other product variants or sub‑products are listed in the CVE data.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity, and an EPSS score of less than 1% suggests that, at the time of this analysis, the probability of real‑world exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The plugin’s code is executed on every request to the site’s admin or document pages, so the most likely attack vector would be a remote web request that targets a URL served by the WP Docs plugin. While the find‑ability of the flaw is short‑lived, the lack of immediate exploit in the public domain means monitoring remains prudent.

Generated by OpenCVE AI on May 1, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Docs to version 2.2.7 or newer to eliminate the missing authorization checks.
  • After the upgrade, test that all previously restricted documents are no longer accessible to anonymous visitors.
  • Review and configure the plugin’s role‑based permissions so that only authorized users can view or edit documents.
  • Monitor site access logs for attempts to reach WP Docs URLs that are not permitted and block suspicious IPs if necessary.
  • If the plugin is not essential, consider disabling or removing it to reduce the attack surface.

Generated by OpenCVE AI on May 1, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8712 Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Docs: from n/a through n/a.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Docs: from n/a through n/a. Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < 2.2.7.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 31 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Title WordPress WP Docs plugin < 2.2.7 - Broken Access Control vulnerability

Mon, 31 Mar 2025 06:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Docs: from n/a through n/a.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Fahad Mahmood Wp Docs
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:06.969Z

Reserved: 2025-03-28T11:00:03.509Z

Link: CVE-2025-31417

cve-icon Vulnrichment

Updated: 2025-03-31T12:41:10.686Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T06:15:31.480

Modified: 2026-04-23T15:27:47.527

Link: CVE-2025-31417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T03:30:07Z

Weaknesses