What the vulnerability does
01Description
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with contributor-level access and above, to embed PDF blocks.
Explanation of Vulnerability in Simple Terms
02Summary
EmbedPress versions up to 3.9.12 contain an integrity vulnerability allowing authenticated users with low privileges to modify data they should not have access to. The vulnerability requires network access and valid login credentials but no user interaction. The impact is limited to data modification without affecting confidentiality or availability.
What an attacker can do
03Attacker Capabilities
Modify data within the plugin that should be restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Authenticated users may alter plugin settings or content beyond their intended permission level.
Conditions required to exploit
05Prerequisites
Valid WordPress user account with low-level privileges (e.g., Subscriber or Contributor role).
Key dates
06Disclosure timeline
May 23, 2024
CVE published
April 8, 2026
Record updated