CVE-2025-14980
BaseFortify
Publication date: 2026-01-09
Last updated on: 2026-01-09
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wpbetterdocs | betterdocs | to 4.3.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The BetterDocs plugin for WordPress has a vulnerability in the scripts() function that allows authenticated users with contributor-level access or higher to extract sensitive information, including the OpenAI API key stored in the plugin settings.
How can this vulnerability impact me? :
This vulnerability can lead to sensitive information exposure, specifically allowing attackers with contributor-level access to obtain the OpenAI API key. This could result in unauthorized use of the API key and potential misuse of associated services.
What immediate steps should I take to mitigate this vulnerability?
Update the BetterDocs plugin to version 4.3.4 or later, as this version contains fixes addressing the sensitive information exposure vulnerability. [1]