CVE · Medium

CVE-2024-1803 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1803 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.13 Improper Authorization Medium 4.3 < 3.9.13 3.9.13 2024-05-22

CVE-2024-1803

The EmbedPress plugin versions up to and including 3.9.12 contains an authorization flaw in the PDF embed block that allows authenticated contributors and higher-privileged users to embed PDF blocks without proper permission validation. An attacker with contributor-level access or above could exploit this weakness to embed PDFs, potentially bypassing intended content restrictions. The vulnerability was remedied in version 3.9.13.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.