Vulnerabilities > CVE-2021-24775 - Exposure of Resource to Wrong Sphere vulnerability in Bplugins Document Embedder
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |