CVE-2026-16567 UNKNOWN

CVE-2026-16567

Published: 2026-08-27

Description

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token and streaming the file, allowing unauthenticated attackers to download arbitrary Document Embedder WordPress plugin before 2.3.1 documents, including private and draft ones, by enumerating IDs.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…