← WordPress Vulnerabilities
WordPress security by component

Document Embedder

Document Embedder embeds documents such as PDFs and office files within WordPress pages.

Document Embedder (document-embedder) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 27, 2026; the highest published CVSS base score is 5.3.

Plugin slug: document-embedder

CVE-2026-16567: Document Embedder exposes private and draft documents

Document Embedder before 2.3.1 issues a download token and streams a document without checking its publication status. An unauthenticated attacker can enumerate document IDs and download arbitrary documents, including private and draft files.

PublishedAug 27, 2026
Known safe version2.3.1
Published vulnerabilities for document-embedder
Safe version
Aug 27, 2026 CVE-2026-16567
Document Embedder exposes private and draft documents
Document Embedder before 2.3.1 issues a download token and streams a document without checking its publication status. An unauthenticated attacker can enumerate document IDs and download arbitrary documents, including private and draft files.
2.3.1
CVE5.3
NVDPending
Feb 01, 2022 CVE-2021-24868
Document Embedder: A security weakness
Document Embedder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD4.3
Feb 01, 2022 CVE-2021-24775
Document Embedder: A security weakness
Document Embedder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3