The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wedevs
Wedevs wedocs Wordpress Wordpress wordpress |
|
| Vendors & Products |
Wedevs
Wedevs wedocs Wordpress Wordpress wordpress |
Fri, 09 Jan 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys. | |
| Title | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-09T06:34:56.372Z
Updated: 2026-01-09T19:18:20.856Z
Reserved: 2025-12-12T12:23:59.405Z
Link: CVE-2025-14574
Updated: 2026-01-09T19:18:18.381Z
Status : Received
Published: 2026-01-09T07:16:00.050
Modified: 2026-01-09T07:16:00.050
Link: CVE-2025-14574
No data.