wpdevteam Vulnerabilities and Affected Products
Vulnerabilities associated with BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot.
Products
Clear product- Essential Addons for Elementor – Popular Elementor Templates & Widgets49 vulnerabilities
- Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns22 vulnerabilities
- EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more17 vulnerabilities
- BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor5 vulnerabilities
- NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar5 vulnerabilities
- BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot2 vulnerabilities
- Essential Blocks Pro2 vulnerabilities
- EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more1 vulnerability
- SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher1 vulnerability
- Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15104MEDIUM | BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' ParameterThe BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter in all versions up to, and including, 4.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used … CWE-89Jul 10, 2026 | CVSS6.5v3.1 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12157MEDIUM | BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block AttributeThe BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insufficient input sanitization and output escaping in the CategorySlateLayout::render() method, which echoes the blockId block attribute directly into an HTML class attribute without esc_attr(). This makes it possi… CWE-79Jun 19, 2026 | CVSS6.4v3.1 | EPSS0.349% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |