CVE Database /
CVE-2024-29141
CVE · Medium
CVE-2024-29141 — PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] < 4.7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-29141
|
PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] < 4.7.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.5
|
< 4.7.1
|
4.7.1 |
2024-03-18 |
—
|
CVE-2024-29141
The PDF Embedder plugin for WordPress before version 4.7.1 contains a cross-site scripting flaw that enables attackers to embed malicious scripts into web pages, potentially executing redirects, ads, or arbitrary HTML code when visitors access the site. Steven Julian identified and disclosed this vulnerability, which was remedied in version 4.7.1. Users should upgrade to the patched version to prevent exploitation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings