SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16567

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Document Embedder plugin for WordPress versions prior to 2.3.1 is vulnerable to unauthorized access, allowing attackers to download any document, including private and draft files, by exploiting the lack of status checks before issuing download tokens. This poses a significant risk to the confidentiality of sensitive documents. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.

CVE
CVE-2026-16567
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.