CVE-2025-22696: WordPress Document Block – Upload & Embed Docs, PDF, PPT, XLS or Any Documents plugin <= 1.1.0 - Broken Access Control vulnerability
Published Feb 4, 2025
·Updated
Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through <= 1.1.0.
Affected Software
1 affected component
WPDeveloper Document Block – Upload & Embed Docs<=1.1.0
Event History
Feb 4, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22696?
CVE-2025-22696 is classified as a missing authorization vulnerability, which can lead to unauthorized access to sensitive documents.
2
How do I fix CVE-2025-22696?
To fix CVE-2025-22696, update the EmbedPress Document Block – Upload & Embed Docs plugin to version 1.1.1 or later.
3
Which versions of Document Block – Upload & Embed Docs are affected by CVE-2025-22696?
CVE-2025-22696 affects all versions up to and including 1.1.0.
4
What types of data are at risk due to CVE-2025-22696?
CVE-2025-22696 exposes uploaded documents, which may include PDFs, PPTs, and XLS files to unauthorized access.
5
Where can I find more information about CVE-2025-22696?
More detailed information about CVE-2025-22696 can be found in security advisories and vulnerability databases.