PLUGIN SECURITY

Is Document Emberdder safe?

Embed PDF, Word, Excel, PowerPoint and 16+ file types in WordPress with a responsive viewer, FlipBook mode, download button and document library.

What this plugin does

  • Slug: document-emberdder
  • Author: bPlugins
  • 9000+ active installs
  • 98/100 rating (119 reviews on wordpress.org)
  • 261851 all-time downloads
  • On WordPress.org since 2019-09-10

document embedderdocument libraryembed any documentembed pdfpdf embedder

Maintenance status

  • Latest known version: 2.2.1
  • Last updated: 2026-08-22 9:04am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.1+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

5 known CVEs on file for Document Emberdder.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16567 Document Embedder – let visitors read files without downloading [document-emberdder] < 2.3.1 Authorization Bypass Through User-Controlled Key Unknown < 2.3.1 2.3.1 2026-08-27 ⚠ update needed
CVE-2025-12384 Document Embedder – let visitors read files without downloading [document-emberdder] < 2.0.1 Missing Authorization High 8.6 < 2.0.1 2.0.1 2025-11-04 ✓ fixed in latest
CVE-2021-24775 Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.6 Exposure of Resource to Wrong Sphere Medium 5.3 < 1.7.6 1.7.6 2022-01-03 ✓ fixed in latest
CVE-2021-24868 Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9 Exposure of Resource to Wrong Sphere Medium 4.3 < 1.7.9 1.7.9 2022-01-03 ✓ fixed in latest
Document Embedder – let visitors read files without downloading [document-emberdder] < 2.0.5 Unknown < 2.0.5 2.0.5 0000-00-00 ✓ fixed in latest
CVE-2026-1389 Document Embedder < 2.0.5 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion Unknown < 2.0.5 2.0.5 ✓ fixed in latest

How to fix it

Keep Document Emberdder updated — 2.2.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.