ONLYOFFICE Docs

ONLYOFFICE Docs has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for ONLYOFFICE Docs has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. ONLYOFFICE Docs is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSHigh
8.1/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all ONLYOFFICE Docs vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-6380

ONLYOFFICE Docs 1.1.0 - 2.2.0 - Missing Authorization to Unauthenticated Privilege Escalation via callback Function

Read the full analysis

Vulnerability Records

2 records
ONLYOFFICE Docs banner
Latestv2.3.0

ONLYOFFICE Docs

onlyoffice

Author

onlyoffice

0.0(0)
0/100
Last Updated
2025-07-25 (1y ago)
Active Installs
100+
Downloads
6,400
Requires WP
5.7+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2022-05-11 (4y ago)

ONLYOFFICE Docs plugin allows WordPress administrators to open documents, spreadsheets, and presentations for collaborative editing using ONLYOFFICE Docs (online document editors). In published posts, the editors are visible to all WordPress site visitors (both authorized and unauthorized) in the Embedded mode only. Editing files uploaded to WordPress All uploaded files from the Media section will appear on the ONLYOFFICE Docs -> Files page. The editor opens in the same tab by clicking on the file name. Users with administrator rights are able to co-edit documents. All the changes are saved in the same file. Creating a post When creating a post, you can add the ONLYOFFICE Docs element (block) and then upload a new file or select one from the Media Library. The added file will be displayed as the ONLYOFFICE logo with the file name in the currently edited post. After the post is published (when you press the Publish or Update button), your WordPress site visitors will have access to this file for viewing in the Embedded mode.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C