PT-2026-50843 · WordPress · Betterdocs Pro
CVE-2026-7515
·
Published
2026-06-19
·
Updated
2026-06-22
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BetterDocs Pro versions prior to 3.8.1
Description
The plugin is susceptible to Local File Inclusion, a condition where an application includes files on a local server unexpectedly. Unauthenticated attackers can exploit this via the
doc style parameter to include and execute arbitrary .php files. This may lead to the execution of PHP code, bypassing of access controls, or the acquisition of sensitive data, particularly when .php files can be uploaded to the server.Recommendations
Update to a version later than 3.8.0.
As a temporary workaround, restrict or disable the use of the
doc style parameter.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Betterdocs Pro