PT-2026-44218 · Smub+1 · Pdf Embedder+1

·

CVE-2026-7526

·

Published

2026-05-27

·

Updated

2026-08-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PDF Embedder versions prior to 4.9.4
Description Authenticated attackers with contributor-level access and above can extract configuration data through the enqueue block assets function. If the premium add-on is installed and a key is saved, the license key may be exposed. In Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan.
Recommendations Update PDF Embedder to version 4.9.4 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7526

Affected Products

Pdf Embedder
Pdf Embedder – Pdf Viewer & Embed Pdf Files For Wordpress