The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam betterdocs |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpdevteam Wpdevteam betterdocs |
Fri, 09 Jan 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the scripts() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive data including the OpenAI API key stored in plugin settings. | |
| Title | BetterDocs <= 4.3.3 - Authenticated (Contributor+) Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-09T18:24:39.427Z
Reserved: 2025-12-19T16:27:14.224Z
Link: CVE-2025-14980
Updated: 2026-01-09T18:24:34.900Z
Status : Received
Published: 2026-01-09T07:16:01.913
Modified: 2026-01-09T07:16:01.913
Link: CVE-2025-14980
No data.
OpenCVE Enrichment
Updated: 2026-01-09T13:23:46Z