Known vulnerabilities in Document Embedder – let visitors read files without downloading
Embed PDF, Word, Excel, PowerPoint and 16+ file types in WordPress with a responsive viewer, FlipBook mode, download button and document library.
3Reported vulnerabilities
8.6Highest CVSS score
2.2.1Latest version
9,000+Active installs
What to do now
Update Document Embedder – let visitors read files without downloading to 2.3.1 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-12384 | High | 0.3% | 2.0.0 and earlier | 2.0.1 |
November 4, 2025 |
| CVE-2026-16567 | High | 0.2% | Before 2.3.1 | 2.3.1 |
August 28, 2026 |
| CVE-2026-1389 | Medium | 0.2% | 0 to 2.0.4 (inclusive) | 2.0.5 |
January 28, 2026 |