PLUGIN SECURITY
Is Document Emberdder safe?
Embed PDF, Word, Excel, PowerPoint and 16+ file types in WordPress with a responsive viewer, FlipBook mode, download button and document library.
What this plugin does
- Slug:
document-emberdder - Author: bPlugins
- 9000+ active installs
- 98/100 rating (119 reviews on wordpress.org)
- 261851 all-time downloads
- On WordPress.org since 2019-09-10
document embedderdocument libraryembed any documentembed pdfpdf embedder
Maintenance status
- Latest known version: 2.2.1
- Last updated: 2026-08-22 9:04am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.1+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
5 known CVEs on file for Document Emberdder.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-16567 | Document Embedder – let visitors read files without downloading [document-emberdder] < 2.3.1 | Authorization Bypass Through User-Controlled Key | Unknown | < 2.3.1 | 2.3.1 | 2026-08-27 | ⚠ update needed |
| CVE-2025-12384 | Document Embedder – let visitors read files without downloading [document-emberdder] < 2.0.1 | Missing Authorization | High 8.6 | < 2.0.1 | 2.0.1 | 2025-11-04 | ✓ fixed in latest |
| CVE-2021-24775 | Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.6 | Exposure of Resource to Wrong Sphere | Medium 5.3 | < 1.7.6 | 1.7.6 | 2022-01-03 | ✓ fixed in latest |
| CVE-2021-24868 | Document Embedder – let visitors read files without downloading [document-emberdder] < 1.7.9 | Exposure of Resource to Wrong Sphere | Medium 4.3 | < 1.7.9 | 1.7.9 | 2022-01-03 | ✓ fixed in latest |
| — | Document Embedder – let visitors read files without downloading [document-emberdder] < 2.0.5 | — | Unknown | < 2.0.5 | 2.0.5 | 0000-00-00 | ✓ fixed in latest |
| CVE-2026-1389 | Document Embedder < 2.0.5 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion | — | Unknown | < 2.0.5 | 2.0.5 | — | ✓ fixed in latest |
How to fix it
Keep Document Emberdder updated — 2.2.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Document Library Lite — 4000+ active installs — 80/100 (11) — max PHP 8.4
- CatFolders Document Gallery & PDF Library — 3000+ active installs — 90/100 (14) — max PHP 8.4
- User Private Files – Secure Client Portal & File Sharing for WordPress — 1000+ active installs — 88/100 (56) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.