CVE Database /
CVE-2021-24868
CVE · Medium
CVE-2021-24868 — Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24868
|
Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9 |
Exposure of Resource to Wrong Sphere |
Medium
4.3
|
< 1.7.9
|
1.7.9 |
2022-01-03 |
—
|
CVE-2021-24868
The Document Embedder WordPress plugin versions prior to 1.7.9 expose an AJAX endpoint that enables any user with authentication privileges, including those with subscriber-level access, to discover and list the titles of unpublished posts and private posts that should otherwise be restricted from view.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings