CVE-2021-24775: Document Embedder < 1.7.5 - Unauthenticated Arbitrary Private/Draft Post Title Disclosure
Published Feb 1, 2022
·Updated
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
Affected Software
1 affected component
bPlugins Document Embedder Wordpress<1.7.5
Event History
Feb 1, 2022
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
Description
Frequently Asked Questions
1
What is CVE-2021-24775?
CVE-2021-24775 is a vulnerability in the Document Embedder WordPress plugin before version 1.7.5.
2
What is the severity of CVE-2021-24775?
The severity of CVE-2021-24775 is medium with a CVSS score of 5.3.
3
How can an attacker exploit CVE-2021-24775?
An unauthenticated attacker can exploit CVE-2021-24775 by using the REST endpoint in the Document Embedder WordPress plugin to enumerate the title of arbitrary private and draft posts.
4
What is the affected software?
The affected software is the Document Embedder WordPress plugin before version 1.7.5.
5
Is there a fix for CVE-2021-24775?
Yes, updating the Document Embedder WordPress plugin to version 1.7.5 or later will fix CVE-2021-24775.