Impact
BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is compromised by a stored cross‑site scripting flaw that allows an authenticated contributor or higher to inject malicious web scripts into page content. The flaw exists in all releases up to 4.8.1 because the plugin fails to sanitize or escape the heading 'id' attribute before persisting and later echoing it in the Table of Contents. When a user views the injected page, the stored payload is decoded and output unescaped, executing arbitrary JavaScript in the viewer’s browser.
Affected Systems
The affected vendor is wpdevteam, and the product is the BetterDocs plugin for WordPress. All installed copies of BetterDocs up to and including version 4.8.1 are vulnerable. Users running any earlier release are not impacted, while those on later releases that incorporate the fix are safe.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity, and the vulnerability is listed in no KEV catalog. Although the EPSS score is not available, the need for contributor‑level access means that the attack surface is limited to users with certain editing privileges. The stored XSS can lead to theft of session cookies, defacement, or execution of arbitrary scripts, compromising confidentiality and integrity of the site’s users. Given the straightforward injection path via heading tags and the lack of output escaping, the risk remains significant for any site still running a vulnerable BetterDocs version.
OpenCVE Enrichment