The plugin contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
As any authenticated user (1764 being the ID of a private/draft post) https://example.com/wp-admin/admin-ajax.php?action=pdfp_get_doc_meta&id=1764
apple502j
apple502j
Yes
2022-01-03 (about 1 years ago)
2022-01-03 (about 1 years ago)
2022-04-13 (about 1 years ago)