CVE-2025-6380 | OnlyOffice Docs Plugin up to 2.2.0 on WordPress REST Endpoint oo.callback authorization

SecurityVulns

A vulnerability has been found in OnlyOffice Docs Plugin up to 2.2.0 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file oo.callback of the component REST Endpoint. The manipulation leads to missing authorization.

This vulnerability is known as CVE-2025-6380. The attack can be launched remotely. There is no exploit available.VulDB Recent EntriesRead More