cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpdf-embedder pdf-embedder

Direction: ascending
Jun 07, 2024

PDF Embedder # CVE-2024-4367

CVE, Research URL

CVE-2024-4367

Application

PDF Embedder

Date
May 14, 2024
Research Description
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Affected versions
Min -, max -.
Status
vulnerable

PDF Embedder # CVE-2019-19589

CVE, Research URL

CVE-2019-19589

Application

PDF Embedder

Date
Dec 05, 2019
Research Description
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder.
Affected versions
Min -, max -.
Status
vulnerable

PDF Embedder # CVE-2024-29141

CVE, Research URL

CVE-2024-29141

Application

PDF Embedder

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PDF Embedder allows Stored XSS.This issue affects PDF Embedder: from n/a through 4.6.4.
Affected versions
Min -, max -.
Status
vulnerable
Sep 11, 2025

PDF Embedder # PSC-2025-64596

PSC, Research URL

PSC-2025-64596

Application

PDF Embedder

Date
Sep 11, 2025
Research Description
PDF Embedder is a powerful WordPress plugin that allows you to upload and embed PDF files directly into posts and pages, offering seamless document presentation with responsive design. Unlike other plugins that rely on iframes, PDF Embedder uses a unique JavaScript-based rendering method that gives site administrators complete control over the look, sizing, and navigation of embedded PDFs. The plugin ensures that all PDF files and associated scripts are served from your own server, guaranteeing both faster performance and greater reliability, without reliance on third-party services. This approach enhances not only the user experience but also the security of your content. The free version includes essential embedding functionality, while PDF Embedder Premium extends features with download options, hyperlink support, continuous scrolling, full-screen mode, and advanced mobile-friendly options.
Affected versions
Min -, max -.
Status
SAFE & CERTIFIED