CVE-2021-24868: Document Embedder < 1.7.9 - Subscriber+ Arbitrary Private/Draft Post Title Disclosure
Published Feb 1, 2022
·Updated
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
Affected Software
1 affected component
bPlugins Document Embedder Wordpress<1.7.9
Event History
Feb 1, 2022
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24868.
2
What is the severity of CVE-2021-24868?
The severity of CVE-2021-24868 is medium.
3
What is the affected software?
The affected software is the Document Embedder WordPress plugin before version 1.7.9.
4
How can an attacker exploit CVE-2021-24868?
An attacker can exploit CVE-2021-24868 by using the AJAX action endpoint to enumerate the title of arbitrary private and draft posts.
5
Is authentication required to exploit CVE-2021-24868?
Yes, authentication is required to exploit CVE-2021-24868.