Description
The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2025-12-11: | Discovered |
| 2025-12-12: | Vendor Notified |
| 2026-01-08: | Disclosed |
Credits
German
References
www.wordfence.com/...-0985-43d3-855e-eee07715f670?source=cve
plugins.trac.wordpress.org/...5&new_path=/wedocs/tags/2.1.16