WordPress security by component
Document Embedder
Plugin description
Document Embedder embeds documents such as PDFs and office files within WordPress pages.
Document Embedder (document-embedder) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Aug 27, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
document-embedderLatest vulnerability
CVE-2026-16567: Document Embedder exposes private and draft documents
Document Embedder before 2.3.1 issues a download token and streams a document without checking its publication status. An unauthenticated attacker can enumerate document IDs and download arbitrary documents, including private and draft files.
| Safe version |
|
||
|---|---|---|---|
| Aug 27, 2026 |
CVE-2026-16567
Document Embedder exposes private and draft documents
Document Embedder before 2.3.1 issues a download token and streams a document without checking its publication status. An unauthenticated attacker can enumerate document IDs and download arbitrary documents, including private and draft files.
|
2.3.1 |
CVE5.3
NVDPending
|
| Feb 01, 2022 |
CVE-2021-24868
Document Embedder: A security weakness
Document Embedder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Feb 01, 2022 |
CVE-2021-24775
Document Embedder: A security weakness
Document Embedder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD5.3
|