WordPress Plugin Vulnerabilities

Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Token Oracle

Description

The plugin does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary plugin documents, including private and draft ones, by enumerating IDs.

Proof of Concept

Affects Plugins

Fixed in 2.3.1

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Vaibhav Narkhede
Submitter
Vaibhav Narkhede
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 2 days ago)
Added
2026-08-25 (about 1 day ago)
Last Updated
2026-08-25 (about 1 day ago)

Other