Home/Research/CVEs/CVE-2025-11174 | Missing Auth in Document Library Lite

CVE-2025-11174 | Missing Auth in Document Library Lite

CVE-2025-11174: Missing authorization in Document Library Lite exposes sensitive data. CVSS 5.3. Full vulnerability analysis and remediation by Kai Aizen.

TL;DR
This vulnerability has been assigned CVE-2025-11174 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).
CVE Disclosures →

Status

This vulnerability has been assigned CVE-2025-11174 and is currently pending full publication details from the National Vulnerability Database (NVD). The vulnerability was discovered and responsibly disclosed by Kai Aizen (SnailSploit).

Description

Full technical details will be published once the vulnerability information is released by NVD and the affected software vendor has had adequate time to patch and notify users.

Timeline

  • Discovery: Vulnerability discovered during WordPress plugin security assessment
  • Disclosure: Responsibly disclosed to plugin developer
  • CVE Assignment: CVE-2025-11174 assigned
  • Status: Awaiting NVD publication

Updates

This page will be updated with complete technical details, proof of concept, and remediation guidance once the information is publicly available through NVD.

For the most current information, check the official NVD entry or contact [email protected].

References

Discovered by: Kai Aizen (SnailSploit)

cite this work
BibTeX
@misc{aizen2026cve,
  author = {Aizen, Kai},
  title  = {CVE-2025-11174 | Missing Auth in Document Library Lite},
  year   = {2026},
  url    = {https://snailsploit.com/security-research/cves/cve-2025-11174/},
  note   = {snailsploit.com}
}
APA

Aizen, K. (2026). CVE-2025-11174 | Missing Auth in Document Library Lite. snailsploit.com. https://snailsploit.com/security-research/cves/cve-2025-11174/

MLA

Aizen, Kai. "CVE-2025-11174 | Missing Auth in Document Library Lite." snailsploit, 2026, https://snailsploit.com/security-research/cves/cve-2025-11174/.

Chicago

Aizen, Kai. "CVE-2025-11174 | Missing Auth in Document Library Lite." snailsploit (blog). 2026. https://snailsploit.com/security-research/cves/cve-2025-11174/.

Permalink: https://snailsploit.com/security-research/cves/cve-2025-11174/
disclosure context
all disclosures
CVE Ledger →
23 published CVEs across container, web, OSS, kernel
advisories
GHSA disclosures →
coordinated security advisories
engage
Pen Testing →
same methodology, your stack
Author
Kai Aizen
Independent offensive security researcher. 23 published CVEs, 5 Linux kernel mainline patches, creator of AATMF / P.R.O.M.P.T / SEF, author of Adversarial Minds.