Vulnerabilities and security researches forpdf-embedder pdf-embedder
Direction: ascendingJun 07, 2024
PDF Embedder # CVE-2024-4367
- CVE, Research URL
- Home page URL
- Application
- Date
- May 14, 2024
- Research Description
- A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PDF Embedder # CVE-2019-19589
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 05, 2019
- Research Description
- The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PDF Embedder # CVE-2024-29141
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 19, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PDF Embedder allows Stored XSS.This issue affects PDF Embedder: from n/a through 4.6.4.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Sep 11, 2025
PDF Embedder # PSC-2025-64596
- PSC, Research URL
- Home page URL
- Application
- Date
- Sep 11, 2025
- Research Description
- PDF Embedder is a powerful WordPress plugin that allows you to upload and embed PDF files directly into posts and pages, offering seamless document presentation with responsive design. Unlike other plugins that rely on iframes, PDF Embedder uses a unique JavaScript-based rendering method that gives site administrators complete control over the look, sizing, and navigation of embedded PDFs. The plugin ensures that all PDF files and associated scripts are served from your own server, guaranteeing both faster performance and greater reliability, without reliance on third-party services. This approach enhances not only the user experience but also the security of your content. The free version includes essential embedding functionality, while PDF Embedder Premium extends features with download options, hyperlink support, continuous scrolling, full-screen mode, and advanced mobile-friendly options.
- Affected versions
-
Min -, max -.
- Status
-
SAFE & CERTIFIED