Impact
The vulnerability is a missing authorization flaw in the WordPress plugin that allows users to upload or embed documents without proper role verification. Attackers who can access the plugin interface can add arbitrary files—such as PDFs, PPTs, or XLSs—potentially exposing sensitive content or enabling further exploits. The weakness is identified as CWE-862, an issue of missing authorization that undermines confidentiality and integrity of the site’s media library.
Affected Systems
WPDeveloper’s Document Block – Upload & Embed Docs plugin, versions n/a through 1.1.0 are affected. Site administrators should check the installed plugin version and confirm if it falls within this range.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack path appears to involve the web-based admin interface of the plugin; an attacker with access to the site’s backend could exploit the missing authorization to upload documents from any source.
OpenCVE Enrichment
EUVD