Unauthorized Access in Document Embedder Plugin for WordPress
CVE-2025-12384
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 November 2025
What is CVE-2025-12384?
The Document Embedder plugin for WordPress is susceptible to unauthorized access, allowing unauthenticated attackers to exploit multiple functions, including 'bplde_save_document_library', 'bplde_get_all', 'bplde_get_single', and 'bplde_delete_document_library'. This vulnerability enables attackers to create, read, update, and delete arbitrary document library posts, potentially leading to data loss and compromised document security. Users are encouraged to update to the latest version to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Document Embedder β Embed PDFs, Word, Excel, and Other Files * <= 2.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved