Server-Side Request Forgery Vulnerability in Embed Any Document Plugin for WordPress
CVE-2025-1043
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 February 2025
What is CVE-2025-1043?
The Embed Any Document plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF), allowing authenticated attackers with Contributor-level access or higher to exploit the ‘embeddoc’ shortcode. This vulnerability permits them to initiate web requests to arbitrary endpoints, potentially enabling unauthorized access and manipulation of internal services, which raises significant security concerns for users relying on this functionality.
Affected Version(s)
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files * <= 2.7.5