Embed Any Document
cpe:2.3:a:awsm:embed_any_document:*:*:*:*:wordpress:*:*
- <= 2.7.5
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the WordPress plugin 'Embed Any Document' - which allows users to embed PDF, Word, PowerPoint, and Excel files. This vulnerability exists in all versions through 2.7.5 and can be exploited by authenticated attackers with Contributor-level access or higher. The issue arises when using the 'embeddoc' shortcode, allowing attackers to send web requests to arbitrary locations from the web application, potentially querying and modifying information from internal services.
Exploitation of this vulnerability could allow authenticated attackers to perform Server-Side Request Forgery, making requests to internal services and potentially accessing or modifying sensitive information.
Users are advised to update the 'Embed Any Document' plugin to version 2.7.6 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.