ONLYOFFICE Docs 1.1.0 – 2.2.0 – Missing Authorization to Unauthenticated Privilege Escalation via callback Function

CVE Details

Basic Information

Title ONLYOFFICE Docs 1.1.0 – 2.2.0 – Missing Authorization to Unauthenticated Privilege Escalation via callback Function
Type cve
Published 2025-07-24T09:22:17.749Z
Modified 2025-07-24T09:22:17.749Z

Product Information

Vendor onlyoffice
Product ONLYOFFICE Docs
Version 1.1.0

CVSS Information

Base Score 9.8 (CRITICAL)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

  • onlyoffice ONLYOFFICE Docs 1.1.0

Additional Information

CWE List CWE-862
Source Wordfence

Description

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify the requester’s identity or capabilities. This makes it possible for unauthenticated attackers to log in as an arbitrary user.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.