CVE-2026-1389
Last modified
CVE-2026-1389 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.4. This is due to the plugin not verifying that a user has permission to access the requested resource in the 'bplde_save_document_library', 'bplde_get_single', and 'bplde_delete_document_library' AJAX actions. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.4. This is due to the plugin not verifying that a user has permission to access the requested resource in the 'bplde_save_document_library', 'bplde_get_single', and 'bplde_delete_document_library' AJAX actions. This makes it possible for authenticated attackers, with Author-level access and above, to read, modify, and delete Document Library entries created by other users, including administrators, via the 'id' parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1389?
How severe is CVE-2026-1389?
How do I fix CVE-2026-1389?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13884Integer overflow in Chromecast in Google Chrome prior to 150…8.8
- CVE-2026-13885Use after free in Skia in Google Chrome on Android prior to …8.8
- CVE-2026-13886Insufficient policy enforcement in Isolated Web Apps in Goog…6.5
- CVE-2026-13887Inappropriate implementation in NFC in Google Chrome on Andr…6.5
- CVE-2026-13888Use after free in Extensions in Google Chrome prior to 150.0…8.8
- CVE-2026-13889Side-channel information leakage in WebAuthentication in Goo…6.5
- CVE-2026-13890Out of bounds read in Chromecast in Google Chrome prior to 1…5.3
- CVE-2026-13891Insufficient validation of untrusted input in Extensions in …7.5
- CVE-2026-13892Inappropriate implementation in Chrome for iOS in Google Chr…6.5
- CVE-2026-13893Insufficient validation of untrusted input in WebUI in Googl…6.5
- CVE-2026-13894Insufficient policy enforcement in Network in Google Chrome …6.5
- CVE-2026-13895Inappropriate implementation in Autofill in Google Chrome pr…4.2
Are you affected by CVE-2026-1389?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
