PT-2026-44218 · Smub+1 · Pdf Embedder+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PDF Embedder versions prior to 4.9.4
Description
Authenticated attackers with contributor-level access and above can extract configuration data through the
enqueue block assets function. If the premium add-on is installed and a key is saved, the license key may be exposed. In Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan.Recommendations
Update PDF Embedder to version 4.9.4 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pdf Embedder
Pdf Embedder – Pdf Viewer & Embed Pdf Files For Wordpress