Executive brief
BetterDocs Pro, a WordPress plugin used to create and manage knowledge bases and documentation, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to run malicious code on the website's server. This could lead to a complete takeover of the site, theft of sensitive customer data, or a total service outage.
Technical details
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion (LFI) via the 'doc_style' parameter in versions up to and including 3.8.0. This vulnerability stems from improper validation of user-supplied input used in PHP include statements (CWE-98). An unauthenticated remote attacker can exploit this to include and execute arbitrary .php files already present on the server. In environments where an attacker can successfully upload a malicious PHP file (e.g., through other plugin features or vulnerabilities), this LFI can be escalated to full Remote Code Execution (RCE), leading to complete system compromise. Users should update to the latest version of the plugin to mitigate this risk.
Affected products
- BetterDocs BetterDocs Pro <= 3.8.0
Timeline
- 2026-06-18: patched: Vendor released security enhancements in version 4.5.4 (approximate based on changelog)
- 2026-06-19: disclosed: Vulnerability published by Wordfence and NVD