WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Pdf Embedder?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Pdf Embedder — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: pdf-embedder
  • 300000+ instalaciones activas

blockembed pdfpdfpdf documentpdf viewer

Estado de mantenimiento

  • Última versión conocida: 5.0.1
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

4 CVEs conocidos registrados para Pdf Embedder. Reportadas entre 2019 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-7526 PDF Embedder [pdf-embedder] < 5.0.0 Exposición de información sensible a un actor no autorizado Media 4,3 < 5.0.0 5.0.0 2026-05-27 ✓ corregido en la última versión
CVE-2024-4367 PDF Embedder [pdf-embedder] < 4.8.0 Comprobación incorrecta de condiciones inusuales o excepcionales Desconocido < 4.8.0 4.8.0 2024-05-14 ✓ corregido en la última versión
CVE-2024-29141 PDF Embedder [pdf-embedder] < 4.7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,5 < 4.7.1 4.7.1 2024-03-18 ✓ corregido en la última versión
CVE-2019-19589 PDF Embedder [pdf-embedder] <= 4.4 Conflicto de interpretación Crítica 9,8 < 4.4 4.4 2019-12-05 ✓ corregido en la última versión

CVE-2026-7526

The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4367

PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check when handling fonts. This makes it possible for authenticated attackers, with contributor-level or above permissions, to execute arbitrary JavaScript if they can successfully trick a user into opening a crafted PDF file.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-29141

Update the WordPress PDF Embedder plugin to the latest available version (at least 4.7.1). Steven Julian discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PDF Embedder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.7.1. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-19589

The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Cómo solucionarlo

Mantén Pdf Embedder actualizado — 5.0.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.