CVE Database /
CVE-2019-19589
CVE · Critical
CVE-2019-19589 — PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] <= 4.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-19589
|
PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] <= 4.4 |
Interpretation Conflict |
Critical
9.8
|
< 4.4
|
4.4 |
2019-12-05 |
—
|
CVE-2019-19589
The Lever PDF Embedder plugin up to version 4.4 fails to prevent the distribution of polyglot PDF files that are simultaneously valid JAR archives. This allows files to be served in a format that could potentially be executed as Java archives rather than remaining restricted to PDF viewing. The plugin relies on WordPress core upload handling without implementing additional validation to detect or block dual-format files at the distribution stage.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings