CVE-2025-6380
Last modified
CVE-2025-6380 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify the requester’s identity or capabilities. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an existing attachment post, but does not verify the requester’s identity or capabilities. This makes it possible for unauthenticated attackers to log in as an arbitrary user.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6380?
How severe is CVE-2025-6380?
How do I fix CVE-2025-6380?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-6377A remote code execution security issue exists in the Rockwel…7.8
- CVE-2025-6378The Responsive Food and Drink Menu plugin for WordPress is v…6.4
- CVE-2025-63783A Broken Object Level Authorization (BOLA) vulnerability was…7.6
- CVE-2025-63784An Open Redirect vulnerability exists in the OAuth callback …6.5
- CVE-2025-63785A DOM-based Cross-Site Scripting (XSS) vulnerability exists …6.1
- CVE-2025-6379The BeeTeam368 Extensions Pro plugin for WordPress is vulner…8.8
- CVE-2025-63800The password change endpoint in Open Source Point of Sale 3.…7.5
- CVE-2025-63807An issue was discovered in weijiang1994 university-bbs (aka …9.8
- CVE-2025-6381The BeeTeam368 Extensions plugin for WordPress is vulnerable…8.8
- CVE-2025-63811An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1…7.5
- CVE-2025-6382The Taeggie Feed plugin for WordPress is vulnerable to Store…6.4
- CVE-2025-63822SirenGPS Android Application 2.19.44 is vulnerable to Incorr…8.1
Are you affected by CVE-2025-6380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
