The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 06:16
Updated : 2026-08-28 18:43
NVD link : CVE-2026-16567
Mitre link : CVE-2026-16567
CVE.ORG link : CVE-2026-16567
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
