CVE · Critical

CVE-2019-19589 — PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] <= 4.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-19589 PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] <= 4.4 Interpretation Conflict Critical 9.8 < 4.4 4.4 2019-12-05

CVE-2019-19589

The Lever PDF Embedder plugin up to version 4.4 fails to prevent the distribution of polyglot PDF files that are simultaneously valid JAR archives. This allows files to be served in a format that could potentially be executed as Java archives rather than remaining restricted to PDF viewing. The plugin relies on WordPress core upload handling without implementing additional validation to detect or block dual-format files at the distribution stage.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.