CVE Database /
CVE-2024-4367
CVE
CVE-2024-4367 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-4367
|
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.3 |
Improper Check for Unusual or Exceptional Conditions |
Unknown
|
< 4.0.3
|
4.0.3 |
2024-05-14 |
—
|
CVE-2024-4367
The EmbedPress plugin prior to version 4.0.3 contains a vulnerability in its bundled PDF.js library that allows authenticated users with contributor permissions or higher to execute arbitrary JavaScript code. The flaw stems from insufficient type validation when processing fonts within PDF files, enabling attackers to inject malicious scripts if they can convince a user to open a specially crafted PDF document. This vulnerability affects installations running versions earlier than 4.0.3 and has been resolved in that version and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings