CVE · Medium

CVE-2021-24868 — Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24868 Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9 Exposure of Resource to Wrong Sphere Medium 4.3 < 1.7.9 1.7.9 2022-01-03

CVE-2021-24868

The Document Embedder WordPress plugin versions prior to 1.7.9 expose an AJAX endpoint that enables any user with authentication privileges, including those with subscriber-level access, to discover and list the titles of unpublished posts and private posts that should otherwise be restricted from view.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.