cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foreazydocs eazydocs

Direction: ascending
Jun 07, 2024

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2024-0248

CVE, Research URL

CVE-2024-0248

Date
Feb 12, 2024
Research Description
The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.
Affected versions
Min -, max -.
Status
vulnerable

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # 913e5bdbb292660af6d5220f0e324f2bd770e8b9

Date
Jul 18, 2023
Research Description
EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin [eazydocs] < 2.3.6 (closed) WordPress EazyDocs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) Update the WordPress EazyDocs plugin to the latest available version (at least 2.2.1). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress EazyDocs Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.2.1.
Affected versions
Min -, max -.
Status
vulnerable

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2023-47549

CVE, Research URL

CVE-2023-47549

Date
Nov 15, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.
Affected versions
Min -, max -.
Status
vulnerable

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2023-6035

CVE, Research URL

CVE-2023-6035

Date
Dec 12, 2023
Research Description
The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
Affected versions
Min -, max -.
Status
vulnerable

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2023-6029

CVE, Research URL

CVE-2023-6029

Date
Jan 15, 2024
Research Description
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2023-47648

CVE, Research URL

CVE-2023-47648

Date
Jan 02, 2025
Research Description
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.3.5.
Affected versions
Min -, max -.
Status
vulnerable
Jul 04, 2024

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2024-3999

CVE, Research URL

CVE-2024-3999

Date
Jul 02, 2024
Research Description
The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Jul 15, 2024

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2024-38720

CVE, Research URL

CVE-2024-38720

Date
Jul 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EazyDocs eazydocs allows Stored XSS.This issue affects EazyDocs: from n/a through 2.5.0.
Affected versions
Min -, max -.
Status
vulnerable

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2024-38721

CVE, Research URL

CVE-2024-38721

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.5.0.
Affected versions
Min -, max -.
Status
vulnerable
Dec 18, 2024

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2024-54376

CVE, Research URL

CVE-2024-54376

Date
Dec 16, 2024
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.
Affected versions
Min -, max -.
Status
vulnerable
Apr 11, 2025

EazyDocs &#8211; Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) # CVE-2025-32221

CVE, Research URL

CVE-2025-32221

Date
Apr 10, 2025
Research Description
Missing Authorization vulnerability in Spider Themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EazyDocs: from n/a through 2.6.4.
Affected versions
Min -, max -.
Status
vulnerable