CVE · Medium

CVE-2024-31274 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31274 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.12 Missing Authorization Medium 5.3 < 3.9.12 3.9.12 2024-04-05

CVE-2024-31274

The EmbedPress plugin for WordPress versions before 3.9.12 contains a broken access control vulnerability that allows unauthorized users to perform actions typically restricted to privileged accounts. The flaw stems from missing authorization, authentication, or nonce token validation in a plugin function. Users should update to version 3.9.12 or later to resolve this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.