CVE-2025-7499: BetterDocs <= 4.1.1 - Missing Authorization to Private And Password-Protected Posts Information Disclosure
The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getresponse function in all versions up to and including 4.1.1. This makes it possible for unauthenticated attackers to retrieve passwords for password-protected documents as well as the metadata of private and draft documents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7499?
The severity of CVE-2025-7499 is considered high due to the risk of unauthorized access to sensitive data.
How do I fix CVE-2025-7499?
To fix CVE-2025-7499, update the BetterDocs plugin to version 4.1.2 or later, which includes the necessary security patches.
What is the vulnerability in CVE-2025-7499?
CVE-2025-7499 is a security vulnerability caused by a missing capability check in the get_response function of the BetterDocs plugin.
Which versions are affected by CVE-2025-7499?
CVE-2025-7499 affects versions of the BetterDocs plugin up to and including version 4.1.1.
Who is the vendor for CVE-2025-7499?
The vendor for CVE-2025-7499 is BetterDocs, which provides the Advanced AI-Driven Documentation tool for WordPress.