The weDocs plugin for WordPress has a security vulnerability that allows unauthorized changes to be made to the data. This is because there is a missing check for permissions on the update_helpfullness REST API endpoint in versions up to 2.1.4. This means that attackers who are not logged in can make changes to the plugin’s settings.