Impact
The weDocs plugin for WordPress fails to enforce proper access control, permitting users to view or modify documents and settings that should be private. The vulnerability arises from incorrectly configured security levels, allowing a malicious actor to access restricted content. Consequently, confidentiality is compromised and integrity may be affected if documents or plugin configurations are altered.
Affected Systems
All installations of the weDevs weDocs plugin with version 2.1.18 or earlier on WordPress sites are affected. The issue is present across every build of the plugin prior to 2.1.19, regardless of other components or site configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring crafted HTTP requests to the plugin’s endpoints; no login or privileged credentials are required, so the risk is moderate and timely remediation is advised.
OpenCVE Enrichment