First published: Thu Feb 20 2025(Updated: )
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files | <=2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1043 is considered a critical vulnerability due to the potential for Server-Side Request Forgery that can be exploited by authenticated attackers.
To fix CVE-2025-1043, update the Embed Any Document plugin to version 2.7.6 or later.
CVE-2025-1043 affects all versions of the Embed Any Document plugin for WordPress up to and including version 2.7.5.
CVE-2025-1043 is a Server-Side Request Forgery (SSRF) vulnerability.
Exploitation of CVE-2025-1043 may allow attackers to manipulate server requests, leading to unauthorized access to sensitive data.