ONLYOFFICE Docs
ONLYOFFICE Docs has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for ONLYOFFICE Docs has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. ONLYOFFICE Docs is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-6380ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback Function
Read the full analysisVulnerability Records

ONLYOFFICE Docs
Author
onlyoffice
ONLYOFFICE Docs plugin allows WordPress administrators to open documents, spreadsheets, and presentations for collaborative editing using ONLYOFFICE Docs (online document editors). In published posts, the editors are visible to all WordPress site visitors (both authorized and unauthorized) in the Embedded mode only. Editing files uploaded to WordPress All uploaded files from the Media section will appear on the ONLYOFFICE Docs -> Files page. The editor opens in the same tab by clicking on the file name. Users with administrator rights are able to co-edit documents. All the changes are saved in the same file. Creating a post When creating a post, you can add the ONLYOFFICE Docs element (block) and then upload a new file or select one from the Media Library. The added file will be displayed as the ONLYOFFICE logo with the file name in the currently edited post. After the post is published (when you press the Publish or Update button), your WordPress site visitors will have access to this file for viewing in the Embedded mode.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C