🔐 CVE Alert

CVE-2025-11997

MEDIUM 5.3

Document Pro Elementor – Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information Exposure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Document Pro Elementor – Documentation & Knowledge Base plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.9. This is due to the plugin exposing sensitive Algolia API keys through the frontend JavaScript code via wp_localize_script without proper access restrictions. This makes it possible for unauthenticated attackers to view sensitive API keys in the page source, which could be leveraged to make unauthorized API calls to the configured Algolia search service.

CWE CWE-200
Vendor ngothoai
Product document pro elementor – documentation & knowledge base
Published Nov 11, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for ngothoai document pro elementor – documentation & knowledge base

Be the first to know when new medium vulnerabilities affecting ngothoai document pro elementor – documentation & knowledge base are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ngothoai / Document Pro Elementor – Documentation & Knowledge Base
0 ≤ 1.0.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/5ac7455a-0c89-4f5b-84eb-b7cc87bce8d4?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/document-pro-elementor/tags/1.0.9/inc/Base/DPET_Enqueue.php#L85 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/document-pro-elementor/tags/1.0.9/inc/Base/DPET_Enqueue.php#L71

Credits

Nabil Irawan