Input validation vulnerability in Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files 2.7.5

A plugin for WordPress called Embed Any Document, which allows users to embed PDF, Word, PowerPoint, and Excel files, has a security vulnerability. This issue, known as Server-Side Request Forgery, affects all versions up to 2.7.5 and can be triggered by using the ’embeddoc’ shortcode. This means that attackers who are logged in as Contributors or higher can make requests to any location on the web, potentially accessing and altering internal information.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.