CVE

CVE-2024-4367 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4367 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.0.3 Improper Check for Unusual or Exceptional Conditions Unknown < 4.0.3 4.0.3 2024-05-14

CVE-2024-4367

The EmbedPress plugin prior to version 4.0.3 contains a vulnerability in its bundled PDF.js library that allows authenticated users with contributor permissions or higher to execute arbitrary JavaScript code. The flaw stems from insufficient type validation when processing fonts within PDF files, enabling attackers to inject malicious scripts if they can convince a user to open a specially crafted PDF document. This vulnerability affects installations running versions earlier than 4.0.3 and has been resolved in that version and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.