{
 "id": "WPSEC-2026-0688",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0688/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0688/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0688/index.md",
 "title": "BetterDocs <= 4.9.3 - Unauthenticated Sensitive Information Exposure via Private and Draft Doc Titles",
 "description": "The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure via single doc request handling in all versions up to, and including, 4.9.3. This is due to the reapply_taxonomy_flags() and prevent_404_status() functions marking a doc request that carries a doc_category query var as a singular doc, setting the doc looked up by slug as the queried object, and turning the 404 into a 200, even when the main query returned no posts because the doc is private, draft or otherwise not readable by the visitor. This makes it possible for unauthenticated attackers to view the titles of private, draft or pending docs whose slugs they know or can guess. The titles appear in the page title and breadcrumbs.",
 "plugin": {
  "slug": "betterdocs",
  "name": "BetterDocs",
  "full_name": "BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot",
  "wordpress_org": "https://wordpress.org/plugins/betterdocs/",
  "advisories_url": "https://wpsec.com/vuln/plugin/betterdocs/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/betterdocs"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.9.4",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.9.4"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.9.4",
 "remediation": "Update to 4.9.4 or later.",
 "fix_released": "2026-10-08T06:41:13+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:52:56.688742+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0688/",
  "https://plugins.svn.wordpress.org/betterdocs/tags/4.9.4/",
  "https://wordpress.org/plugins/betterdocs/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/betterdocs",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}