CVE · High

CVE-2024-38707 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-38707 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.5 Missing Authorization High 8.8 < 4.0.5 4.0.5 2024-07-11

CVE-2024-38707

The EmbedPress plugin contains a vulnerability in versions up to 4.0.4 where several functions including get_instagram_userdata_ajax, sync_instagram_data_ajax, and delete_instagram_account lack proper capability checks. This flaw allows authenticated users with subscriber-level permissions or higher to make unauthorized changes to Instagram account settings. The issue was resolved in version 4.0.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.