CVE-2026-16567
Received Received - Intake

Unauthenticated File Download in Document Embedder WordPress Plugin

Vulnerability report for CVE-2026-16567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
document_embedder document_embedder to 2.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin Document Embedder before version 2.3.1. It allows unauthenticated attackers to download arbitrary documents, including private or draft ones, by exploiting a flaw where the plugin does not check a document's status before issuing a download token and streaming the file. Attackers can access documents by enumerating document IDs.

Detection Guidance

Check if your WordPress site uses the Document Embedder plugin version prior to 2.3.1. Inspect network traffic for unauthorized document downloads or unusual access patterns to document endpoints.

Impact Analysis

If you use the affected Document Embedder plugin, attackers could access sensitive documents you intended to keep private or unpublished. This includes confidential files, draft content, or restricted materials, potentially leading to data leaks or unauthorized disclosures.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing protected or personal data. Unauthorized access to private documents may violate confidentiality requirements, leading to legal penalties, fines, or reputational damage for organizations handling sensitive information.

Mitigation Strategies

Update the Document Embedder plugin to version 2.3.1 or later immediately. Review document access logs for suspicious activity and restrict unauthenticated access to sensitive documents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart