Description
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11780 | The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:49:14.356Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-24868
No data.
Status : Modified
Published: 2022-02-01T13:15:08.673
Modified: 2024-11-21T05:53:55.247
Link: CVE-2021-24868
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD