CVE-2025-6380

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify the requester’s identity or capabilities. This makes it possible for unauthenticated attackers to log in as an arbitrary user.
Configurations

No configuration.

History

No history.

Information

Published : 2025-07-24 10:15

Updated : 2025-07-25 15:29


NVD link : CVE-2025-6380

Mitre link : CVE-2025-6380

CVE.ORG link : CVE-2025-6380


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization