CVE-2025-31417: WordPress WP Docs plugin < 2.2.7 - Broken Access Control vulnerability
Published Mar 31, 2025
·Updated
Missing Authorization vulnerability in Fahad Mahmood WP Docs wp-docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through < 2.2.7.
Affected Software
1 affected component
Fahad Mahmood WP Docs<2.2.7
Remediation
Information
Update the WordPress WP Docs plugin to the latest available version (at least 2.2.7).
Event History
Mar 31, 2025
CVE Published
via MITRE·06:06 AM
Data Sourced
via MITRE·06:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-31417?
CVE-2025-31417 is classified as a missing authorization vulnerability that can lead to incorrect access control security levels.
2
How do I fix CVE-2025-31417?
To fix CVE-2025-31417, update the WP Docs plugin to the latest version that addresses the broken access control issue.
3
What is the impact of CVE-2025-31417?
The impact of CVE-2025-31417 can lead to unauthorized access to sensitive documents within the WP Docs environment.
4
Which versions of WP Docs are affected by CVE-2025-31417?
CVE-2025-31417 affects WP Docs version 2.2.7 and earlier.
5
Who is the vendor responsible for CVE-2025-31417?
The vendor responsible for CVE-2025-31417 is WordPress, specifically through the WP Docs plugin.