PT-2019-15878 · Lever+1 · Lever Pdf Embedder+1

Published

2019-12-05

·

Updated

2024-08-05

·

CVE-2019-19589

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Lever PDF Embedder plugin version 4.4 for WordPress
Description The issue concerns the distribution of polyglot PDF documents that are valid JAR archives. However, it has been argued that the plugin itself does not control the file upload process, and the responsibility of uploading PDF files remains with the site owner of the WordPress installation. The upload of PDF files is managed by WordPress core, not by the PDF Embedder Plugin. The control and block of polyglot files are required to be taken care of at the time of upload, not when showing the file.
Recommendations For The Lever PDF Embedder plugin version 4.4, consider implementing controls at the time of PDF file upload to block polyglot files, as the plugin itself does not manage this process. Ensure that WordPress core settings are configured to restrict the upload of potentially malicious files. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-19589

Affected Products

Lever Pdf Embedder
Wordpress