HomeWordPress vulnerabilitiesPDF Embedder
PDF Embedder vulnerabilities
PDF Embedder has 2 known vulnerabilities in this database. The most recent published record is dated 28 May 2026.
- Known vulnerabilities
- 2
- Active installs
- 300,000+
- Latest version
- 5.0.2
- Last updated
- 14 Aug 2026
- Most recent
- 28 May 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-7526 | Medium 4.3 | Up to 4.9.3 | Fixed in a later version (latest 5.0.2) | 28 May 2026 |
| Security weakness CVE-2019-19589 | Critical 9.8 | Not yet published | Check for an update | 5 Dec 2019 |
Read the published descriptions
- CVE-2026-7526, 28 May 2026
- The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan. CVE record
- CVE-2019-19589, 5 Dec 2019
- The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder. CVE record
What to do if you run PDF Embedder
If you run PDF Embedder, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new PDF Embedder vulnerabilities
Free. We email you when a new vulnerability is published for PDF Embedder, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.