CVE · Medium

CVE-2025-11174 — Document Library Lite [document-library-lite] < 1.1.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11174 Document Library Lite [document-library-lite] < 1.1.7 Improper Authorization Medium 5.3 < 1.1.7 1.1.7 2025-10-31

CVE-2025-11174

The Document Library Lite plugin for WordPress contains a flaw in its authorization mechanism that affects all versions up to 1.1.6. Specifically, an attacker can exploit the dll_load_posts AJAX action by manipulating the args array's status option to bypass authentication checks. As a result, unauthenticated users can obtain unpublished document metadata through this vulnerable endpoint.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.