logo

CVE-2026-7515: BetterDocs Pro WordPress Plugin — Unauthenticated Local File Inclusion

ID: f009c726-386f-532f-9af7-291de3a4e915

STIX ID: report--f009c726-386f-532f-9af7-291de3a4e915

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

**CVE-2026-7515 — BetterDocs Pro Unauthenticated LFI (CVSS 9.8):** A critical Local File Inclusion vulnerability in the BetterDocs Pro WordPress plugin (affecting versions up to 3.8.0) allows unauthenticated attackers to specify arbitrary PHP files via the doc_style parameter, enabling Remote Code Execution and full server compromise; immediate remediation includes updating above 3.8.0 or deactivating the plugin, auditing uploads, blocking PHP execution in uploads, and deploying WAF/file integrity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.