CVE · Critical

CVE-2024-43328 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43328 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.10 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 4.0.10 4.0.10 2024-08-16

CVE-2024-43328

The EmbedPress plugin for WordPress prior to version 4.0.10 contains a local file inclusion vulnerability accessible through the 'page_type' parameter that does not require authentication. Attackers can exploit this flaw to include and execute arbitrary files on the server, potentially running any PHP code they choose. This vulnerability allows circumvention of access restrictions, theft of confidential information, or arbitrary code execution when safe file types like images are uploaded and subsequently included.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.