plugin

Embed Any Document Vulnerabilities

8 known security issues reported for the Embed Any Document WordPress plugin. Most recent disclosed Dec 18, 2025.

4 medium

Running Embed Any Document on your site? Check whether your installed version is affected.

Scan your site free

Embed Any Document &#8211; Embed PDF, Word, PowerPoint and Excel Files [embed-any-document] < 2.7.11

unknown

[en] The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes it possible for a...

Affected:
up to 2.7.11
Fixed in:
2.7.11
Disclosed:
Dec 18, 2025

CVE-2025-12885 on NVD →

Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sanitize_pdf_src function regex bypass in all versions up to, and including, 2.7.10 due to insufficient input sanitization and output escaping. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 2.7.10
Fixed in:
2.7.11
Disclosed:
Dec 17, 2025

CVE-2025-12885 on NVD →

Embed Any Document <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Embed Any Document plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 2.7.7
Fixed in:
2.7.8
Disclosed:
Sep 26, 2025

CVE-2025-60099 on NVD →

Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode

medium

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web reques...

CVSS:
6.4
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Feb 19, 2025

CVE-2025-1043 on NVD →

Embed Any Document &#8211; Embed PDF, Word, PowerPoint and Excel Files [embed-any-document] < 2.7.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any D...

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Mar 23, 2023

CVE-2023-23707 on NVD →

Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files <= 2.7.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG files

medium

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG files in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level ac...

CVSS:
6.4
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Mar 14, 2023

CVE-2023-23707 on NVD →

Embed Any Document &#8211; Embed PDF, Word, PowerPoint and Excel Files [embed-any-document] < 2.7.6

unknown
Affected:
up to 2.7.6
Fixed in:
2.7.6

CVE-2025-1043 on NVD →

Embed Any Document &#8211; Embed PDF, Word, PowerPoint and Excel Files [embed-any-document] < 2.7.8 (unfixed)

unknown
Affected:
up to 2.7.8
Fix:
No patched version reported

CVE-2025-60099 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database