PT-2026-55440 · WordPress · Betterdocs Pro+2

·

CVE-2026-12729

·

Published

2026-07-03

·

Updated

2026-07-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot versions prior to 2.3.1
Description The plugin contains a missing authorization flaw. The do migration() function, registered as the wedocs migrate betterdocs to wedocs AJAX action, fails to perform nonce verification via check ajax referer() and does not implement capability checks using current user can(). This allows authenticated users with Subscriber-level access or higher to trigger a full data migration from BetterDocs to weDocs. Consequently, an attacker can create or modify 'docs' custom post type entries with arbitrary titles, update site options, and deactivate the BetterDocs and BetterDocs Pro plugins using the deactivate plugins() function.
Recommendations Update to a version newer than 2.3.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12729

Affected Products

Betterdocs
Betterdocs Pro
Wedocs