Junglewise Threat Intelligence

CVE-2026-7526: PDF Embedder WordPress plugin sensitive information exposure

CVE-2026-7526 · Severity: medium · CVSS 4.3 · Published 2026-05-28

Executive brief

The PDF Embedder plugin for WordPress, which allows users to display PDF files directly on their websites, contains a security flaw that exposes configuration data. An attacker with basic contributor-level access to the site can view internal settings and, if the premium version is used, potentially steal the product license key. This could lead to unauthorized use of paid software features or exposure of site configuration details.

Technical details

The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure (CWE-200) via the 'enqueue_block_assets' function. The vulnerability exists in all versions up to and including 4.9.3. An authenticated attacker with contributor-level permissions or higher can exploit this to extract configuration data. In installations where the premium add-on is active, this includes the exposure of the license key. In the Lite version, the exposure is limited to viewer configuration values such as dimensions, toolbar settings, and usage tracking. A patch has been released in the plugin's trunk.

Affected products

  • WP PDF Embedder PDF Embedder Up to and including 4.9.3

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References