PT-2024-18319 · WordPress · Embedpress
Ancorn
+2
·
Published
2024-05-23
·
Updated
2025-01-07
·
CVE-2024-1803
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress versions up to, and including, 3.9.12
Description
The issue is related to insufficient authorization validation on the PDF embed block, allowing authenticated attackers with contributor-level access and above to embed PDF blocks. This enables unauthorized access to functionality.
Recommendations
For versions up to, and including, 3.9.12, update to a version higher than 3.9.12 to resolve the issue. As a temporary workaround, consider restricting access to the PDF embed block to prevent unauthorized embedding of PDF blocks.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Embedpress