Document Embedder <= 2.0.4 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion
medium
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.4. This is due to the plugin not verifying that a user has permission to access the requested resource in the 'bplde_save_document_library', '...
- CVSS:
- 4.3
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jan 27, 2026
CVE-2026-1389 on NVD →
Document Embedder – Embed PDFs, Word, Excel, and Other Files [document-emberdder] < 2.0.1
unknown
[en] The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "bplde_save_docume...
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 5, 2025
CVE-2025-12384 on NVD →
Document Embedder – Embed PDFs, Word, Excel, and Other Files <= 2.0.0 - Missing Authorization to Unauthenticated Document Manipulation
high
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "bplde_save_document_li...
- CVSS:
- 8.6
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Nov 4, 2025
CVE-2025-12384 on NVD →
Document Embedder – Embed PDFs, Word, Excel, and Other Files [document-emberdder] < 1.7.6
unknown
[en] The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Feb 1, 2022
CVE-2021-24775 on NVD →
Document Embedder – Embed PDFs, Word, Excel, and Other Files [document-emberdder] < 1.7.9
unknown
[en] The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Feb 1, 2022
CVE-2021-24868 on NVD →
Document Embedder < 1.7.6 - Sensitive Data Exposure
medium
The Document Embedder WordPress plugin before 1.7.6 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
- CVSS:
- 5.3
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.6
- Disclosed:
- Jan 3, 2022
CVE-2021-24775 on NVD →
Document Embedder <= 1.7.8 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure
medium
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
- CVSS:
- 4.3
- Affected:
- up to 1.7.9
- Fixed in:
- 1.7.9
- Disclosed:
- Jan 3, 2022
CVE-2021-24868 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database