CVE Database /
CVE-2024-43328
CVE · Critical
CVE-2024-43328 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43328
|
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.10 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Critical
9.8
|
< 4.0.10
|
4.0.10 |
2024-08-16 |
—
|
CVE-2024-43328
The EmbedPress plugin for WordPress prior to version 4.0.10 contains a local file inclusion vulnerability accessible through the 'page_type' parameter that does not require authentication. Attackers can exploit this flaw to include and execute arbitrary files on the server, potentially running any PHP code they choose. This vulnerability allows circumvention of access restrictions, theft of confidential information, or arbitrary code execution when safe file types like images are uploaded and subsequently included.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings