CVE-2024-1803 MEDIUM

CVE-2024-1803: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual

Vendor Wpdevteam
Product EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
Weakness CWE-285
Published May 23, 2024
Last update April 8, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including, 3.9.12. This makes it possible for authenticated attackers, with contributor-level access and above, to embed PDF blocks.

Explanation of Vulnerability in Simple Terms

02Summary

EmbedPress versions up to 3.9.12 contain an integrity vulnerability allowing authenticated users with low privileges to modify data they should not have access to. The vulnerability requires network access and valid login credentials but no user interaction. The impact is limited to data modification without affecting confidentiality or availability.

What an attacker can do

03Attacker Capabilities

Modify data within the plugin that should be restricted to higher-privilege users.

Potential impact on your site

04Site Impact

Authenticated users may alter plugin settings or content beyond their intended permission level.

Conditions required to exploit

05Prerequisites

Valid WordPress user account with low-level privileges (e.g., Subscriber or Contributor role).

Key dates

06Disclosure timeline

May 23, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE