PT-2026-82386 · WordPress · Document Embedder
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Document Embedder WordPress plugin versions prior to 2.3.1
Description
The plugin fails to verify the status of a document before generating a download token and streaming the file. This allows unauthenticated attackers to download arbitrary documents, including those marked as private or drafts, by enumerating document IDs.
Recommendations
Update Document Embedder WordPress plugin to version 2.3.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Document Embedder