Executive brief
weDocs is a WordPress plugin used to create and manage documentation for products or services. A security flaw in the plugin's access control settings allows unauthorized individuals to bypass intended security levels. This could lead to the exposure of restricted documentation or information that was meant to be private or limited to specific user roles.
Technical details
The weDocs plugin for WordPress is vulnerable to a missing authorization (CWE-862) flaw in versions up to and including 2.1.18. The vulnerability stems from a failure to properly validate user permissions when accessing components governed by security level configurations. An unauthenticated remote attacker can exploit this to bypass intended access restrictions and view or interact with restricted documentation content. The issue is resolved in version 2.2.1, which introduces proper authorization checks.
Affected products
- weDevs weDocs <= 2.1.18
Timeline
- 2026-01-26: other: Vulnerability reported by researcher hhhai
- 2026-02-25: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE-2026-39520 published
- 2026-02-25: patched: Version 2.2.1 released to address the issue